Executive brief
A vulnerability exists in the Oracle E-Business Suite's Customer Interaction History component, which manages records of customer communications. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive customer data or modify existing records. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Customer Interaction History within Oracle E-Business Suite versions 12.1.1 through 12.1.3. It is an unauthenticated, network-based attack delivered via HTTP. The vulnerability is characterized by a 'Scope' change (S:C) in CVSS terms, meaning an exploit can impact components beyond the immediate Customer Interaction History environment. Successful exploitation requires user interaction (UI:R), such as a victim visiting a malicious URL. Attackers can achieve high confidentiality impact and low integrity impact, allowing for the unauthorized viewing of all accessible data and the modification or deletion of some data.
Affected products
- Oracle E-Business Suite Customer Interaction History 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: advisory: Initial publication of the vulnerability advisory
- 2017-01-27: patched: Oracle released patches as part of the January 2017 Critical Patch Update