Junglewise Threat Intelligence

CVE-2017-3385: Oracle Advanced Outbound Telephony unauthorized data access in User Interface

CVE-2017-3385 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle E-Business Suite's Advanced Outbound Telephony component, which manages automated customer outreach and call center operations. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to customer information or the corruption of telephony records.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit requires human interaction from a person other than the attacker (UI:R) and has a scope impact (S:C), meaning the attack can extend beyond the telephony component to impact other products. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: NVD publication date
  • 2017-01-27: patched: Oracle released patches as part of the January 2017 Critical Patch Update

References

Related threats