Security Vulnerability Allows To Change Some Contents Of Locked Alerts in Transaction Filtering
(Doc ID 2830703.1)
Last updated on MAY 04, 2022
Applies to:
Oracle Financial Services Transaction Filtering - Version 8.0.8.1.0 and laterInformation in this document applies to any platform.
Goal
Security Vulnerability Allows To Change Some Contents Of Locked Alerts in Transaction Filtering
"grpMsgID" parameter to spam all the alerts in the application.
ie.. user accounts get changed in status, comments, attachments on locked alerts by sending requests directly to the API.
Solution
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Goal |
Solution |
References |