Executive brief
A vulnerability exists in the user interface of Oracle One-to-One Fulfillment, a component of the Oracle E-Business Suite used for managing customer communications. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to the unauthorized disclosure of critical information or the alteration of records within the system.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (User Interaction: Required) from a person other than the attacker. The vulnerability has a 'Changed' scope, meaning an exploit can impact components beyond the immediate One-to-One Fulfillment environment. Successful exploitation can result in unauthorized high-impact confidentiality loss (access to all accessible data) and low-impact integrity loss (unauthorized update, insert, or delete access). Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update January 2017 released