HomeSecurityOracle E-Business Suite (EBS): Vulnerabilities discovered

Oracle E-Business Suite (EBS): Vulnerabilities discovered

If your business operations rely on Oracle's E-Business Suite (EBS), make sure you have recently updated and are running the latest available version of the software.

Oracle E-Business Suite (EBS)

In a report released by cybersecurity firm Onapsis, the company today revealed technical details about vulnerabilities present in Oracle's E-Business Suite (EBS), a comprehensive suite of applications designed to automate CRM, ERP, and SCM functions for organizations.

The two vulnerabilities, labeled “BigDebIT” and rated 9.9, were patched by Oracle in a critical patch (CPU) released earlier this January. However, the company said that about 50 percent of Oracle EBS customers have not deployed the patches.

The security flaws could be exploited by hackers to target accounting tools like General Ledger in an attempt to steal sensitive information and commit financial fraud.

According to the researchers, “an unauthorized hacker could execute an automated exploit in the General Ledger module to extract data from a company (such as cash) and modify the accounting tables, without leaving a trace.”

"Successful exploitation of this vulnerability would allow an attacker to steal financial data and cause delays in any financial reporting related to a company," the researchers added.

It is worth noting that the BigDebIT attack vectors "add" to the already reported PAYDAY vulnerabilities in EBS discovered by Onapsis three years ago, with Oracle releasing a series of updates until April 2019.

Reported as CVE-2020-2586 and CVE-2020-2587, the new flaws are found in Oracle Human Resources Management System (HRMS) in a component called Hierarchy Diagrammer, which allows users to create organizational charts related to a business. But together, they can be exploited even if EBS customers have updated their systems with the updates released in April 2019.

"The difference is that with these patches, it is confirmed that even systems that are up to date are vulnerable to these attacks, and therefore the installation of the January CPU should be prioritized," the company said in a statement released in January.

One consequence of these errors, if not addressed, is the possibility of financial fraud and theft of a company's confidential information.

Oracle General Ledger is an automated financial processing that acts as a repository of accounting information and is offered as part of the E-Business Suite, the company's comprehensive suite of applications – covering enterprise resource planning (ERP), supply chain management (SCM), and customer relationship management (CRM) – that users can implement in their own businesses.

General Ledger is also used to create corporate financial reports.

An attacker could exploit any of the flaws and modify critical items on a company's balance sheet.

The news has not yet been officially confirmed by the company.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS