Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

06 / 08 Vulnerability disclosure

Cross-site scripting vulnerability in Oracle Enterprise Command Center

Oracle E-Business Suite – ECC Framework

CVE-2023-22107 is a cross-site scripting flaw in the Oracle Enterprise Command Center (ECC) Framework component of Oracle E-Business Suite. An unauthenticated, network-based attacker who tricks a legitimate user into interacting with a crafted request can execute script in that user's session, gaining unauthorized read and update access to a subset of ECC data and connected products. Oracle fixed it in the October 2023 Critical Patch Update.

Severity: Medium CVSS 6.1 CVE-2023-22107 3 min read

CVSS base score 6.1 Medium

Every score is built from eight plain questions about how an attack works and what it costs you.

How hard it is to exploit

What the attacker can do

Select a metric to see what it means

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

§ 01. Overview

CVE-2023-22107 is a cross-site scripting (XSS) vulnerability in the Enterprise Command Center (ECC) Framework, a component of Oracle E-Business Suite. The ECC Framework provides interactive dashboards and guided data-discovery interfaces that let users navigate transactional information across E-Business Suite modules through visual, faceted components.

Oracle assigned the issue a CVSS 3.1 base score of 6.1 (Medium) with the vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. It affects ECC Framework versions 8, 9, and 10. The vulnerability was disclosed in Oracle's October 2023 Critical Patch Update and is credited to the OffSeq founder as the discoverer.

§ 02. How it works

The root cause is a cross-site scripting weakness (CWE-79): attacker-influenced input is reflected or stored by the ECC Framework and rendered in a user's browser without adequate output encoding or contextual sanitization. As a result, an attacker can supply markup or script that the application emits into an HTML response, where the victim's browser executes it in the trust context of the ECC application origin.

The CVSS vector captures the mechanics precisely. AV:N with PR:N means the attack is delivered over the network by an unauthenticated actor. UI:R indicates that exploitation requires a human other than the attacker to interact — for example, a logged-in ECC user following a crafted link or loading a page containing the injected payload. S:C (scope changed) reflects that code executing in the victim's authenticated session can reach beyond the ECC Framework itself into connected products, which is characteristic of an XSS bug where the vulnerable component and the impacted resources differ. C:L/I:L/A:N indicates limited confidentiality and integrity impact and no direct impact on availability.

§ 03. Impact

Because exploitation runs in the context of the targeted user's authenticated session, a successful attack can result in unauthorized read access and unauthorized update (insert, delete, and modify) access to a subset of data accessible through the ECC Framework. The scope-change property means the consequences are not confined to ECC: the injected script can also affect data belonging to products connected to the framework.

The practical risk profile is that of a session-scoped web attack against E-Business Suite operators. An attacker cannot act directly with the privileges of the application, but by hijacking the interaction of a legitimate user they can perform actions and read data that user is authorized for. The requirement for victim interaction and the limited impact ratings are why the issue is rated Medium rather than High, but ECC deployments typically front sensitive enterprise transactional data, so the exposure is meaningful in real environments.

§ 04. Affected and fixed versions

The vulnerability affects Oracle Enterprise Command Center Framework versions 8, 9, and 10. Oracle addressed it in the Critical Patch Update released in October 2023.

Administrators should apply the relevant October 2023 CPU patches for their ECC Framework version. As with all Oracle CPU items, the fix is only available through the quarterly patch bundle, and Oracle recommends staying current with Critical Patch Updates rather than applying isolated fixes.

§ 05. Disclosure timeline

  1. 2023-10-17 Disclosed in Oracle's October 2023 Critical Patch Update and published to the NVD

Have similar exposure in your environment?

[email protected] +371 2256 5353