Junglewise Threat Intelligence

CVE-2017-3377: Oracle E-Business Suite Advanced Outbound Telephony UI vulnerability

CVE-2017-3377 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a tool used by businesses to manage high-volume customer call campaigns. An attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to the unauthorized disclosure of customer information or the corruption of records within the Oracle E-Business Suite environment.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires user interaction (UI:R) to succeed. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate Outbound Telephony module. Successful exploitation allows an attacker to gain unauthorized read access to sensitive data and perform unauthorized updates, insertions, or deletions of certain data. The vulnerability is present in versions 12.1.1 through 12.2.6 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Addressed in Oracle Critical Patch Update January 2017

References

Related threats