Junglewise Threat Intelligence

CVE-2017-3376: Oracle Advanced Outbound Telephony vulnerability in User Interface

CVE-2017-3376 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the E-Business Suite used for managing high-volume customer communications. An attacker could trick a legitimate user into performing an action that grants the attacker unauthorized access to sensitive business data. This could lead to the theft of customer information or unauthorized changes to telephony records, potentially impacting other integrated business systems.

Technical details

A vulnerability in the User Interface subcomponent of Oracle Advanced Outbound Telephony (part of Oracle E-Business Suite) allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit requires human interaction from a person other than the attacker (UI:R) and results in a scope change (S:C), suggesting a Cross-Site Scripting (XSS) or similar UI-based injection flaw. Successful exploitation can result in unauthorized access to all accessible data or unauthorized modification (update, insert, or delete) of a subset of data. Affected versions include 12.1.1-12.1.3 and 12.2.3-12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update January 2017 released.

References

Related threats