Junglewise Threat Intelligence

CVE-2017-3378: Oracle Advanced Outbound Telephony vulnerability in User Interface

CVE-2017-3378 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a tool used for managing high-volume outbound call center operations. An attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to customer information or the corruption of telephony records, potentially impacting other integrated Oracle E-Business Suite applications.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that can be triggered by an unauthenticated attacker over the network via HTTP. The exploit requires user interaction (UI:R) from a legitimate user, and the 'Scope' is changed (S:C), suggesting a Cross-Site Scripting (XSS) or similar injection-style vulnerability that allows the attacker to bypass security boundaries. Successful exploitation grants the attacker high confidentiality impact (access to all component data) and partial integrity impact (unauthorized modification of some data). Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle January 2017 Critical Patch Update released

References

Related threats