Executive brief
A vulnerability exists in the user interface of Oracle One-to-One Fulfillment, a component of the Oracle E-Business Suite used for managing high-volume customer communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of data confidentiality and integrity across the system.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is classified as an 'easily exploitable' flaw that allows an unauthenticated remote attacker to compromise the system over HTTP. The attack requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the immediate component to other parts of the E-Business Suite. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update or delete access to a subset of that data. Affected versions include 12.1.1-12.1.3 and 12.2.3-12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial publication of the vulnerability by Oracle and NVD.