Executive brief
A vulnerability exists in the Oracle Customer Interaction History component of the Oracle E-Business Suite, which is used by businesses to manage and track customer communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive customer data or modify records, potentially leading to data breaches or loss of data integrity. Exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and the impact can extend beyond the interaction history to other connected business systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Customer Interaction History in Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The attack requires user interaction (UI:R) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning a successful exploit can impact components beyond the immediate Customer Interaction History environment. Attackers can achieve high confidentiality impact and partial integrity impact, resulting in unauthorized access to all accessible data or the ability to update and delete certain records. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Customer Interaction History 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: advisory: Initial disclosure by Oracle
- 2017-01-27: patched: Fix released in January 2017 Critical Patch Update