Executive brief
A vulnerability exists in the Oracle One-to-One Fulfillment component of the Oracle E-Business Suite, which is used for managing high-volume personalized communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to perform an action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated remote attacker to compromise the application via the HTTP protocol. The attack requires human interaction from a person other than the attacker (User Interaction: Required) and features a 'Changed' Scope, meaning the impact can extend beyond the immediate component to other parts of the E-Business Suite environment. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of data. The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle One-to-One Fulfillment (E-Business Suite) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update