Executive brief
A vulnerability exists in the Oracle Customer Interaction History component of the Oracle E-Business Suite, which manages customer contact records and communication logs. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive customer data or modify existing records. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to impact other connected business systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Customer Interaction History (versions 12.1.1, 12.1.2, and 12.1.3). It is classified as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the component. The attack requires human interaction from a person other than the attacker (User Interaction: Required). The vulnerability has a 'Changed' Scope (S:C), meaning an exploit can impact components beyond the immediate Customer Interaction History environment. Successful exploitation can result in unauthorized read access to all data or unauthorized update/delete access to a subset of data. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Customer Interaction History 12.1.1, 12.1.2, 12.1.3
Timeline
- 2017-01-27: advisory: Initial disclosure by Oracle and NVD publication.
- 2017-01-27: patched: Addressed in Oracle Critical Patch Update (CPU) January 2017.