CVE-2017-3528 | Oracle E-Business Suite 12.1.3/12.2.3/12.2.4/12.2.5/12.2.6 Applications Framework /OA_HTML/cabo/jsps/a.jsp redirect access control (EDB-43592 / Nessus ID 99479)
A vulnerability was found in Oracle E-Business Suite 12.1.3/12.2.3/12.2.4/12.2.5/12.2.6. It has been declared as critical. This vulnerability affects unknown code of the file /OA_HTML/cabo/jsps/a.jsp of the component Applications Framework. The manipulation of the argument redirect with the input /\example.com leads to improper access controls.
This vulnerability was named CVE-2017-3528. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.