Junglewise Threat Intelligence

CVE-2017-3443: Oracle Common Applications vulnerability in User Interface

CVE-2017-3443 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Common Applications. Vendors: Oracle.

Executive brief

A vulnerability exists in the User Interface of Oracle Common Applications, a core component of the Oracle E-Business Suite used for enterprise resource planning. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to access, modify, or delete sensitive business data. This could lead to a significant breach of confidentiality and data integrity across multiple integrated Oracle products.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Common Applications within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (User Interaction: Required) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate Oracle Common Applications environment. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Common Applications 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats