Junglewise Threat Intelligence

CVE-2017-3389: Oracle E-Business Suite UI vulnerability in Advanced Outbound Telephony

CVE-2017-3389 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the E-Business Suite used for managing high-volume customer communications. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to unauthorized access to customer information and potentially impact other connected business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is classified as an 'easily exploitable' flaw that can be triggered by an unauthenticated attacker over the network via HTTP. The exploit requires human interaction from a person other than the attacker (UI:R), suggesting a Cross-Site Scripting (XSS) or similar UI-based injection attack. Successful exploitation has a high impact on confidentiality and a partial impact on integrity, with the potential to affect components beyond the immediate application (Scope: Changed). Affected versions include 12.1.1 through 12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial disclosure by Oracle
  • 2017-01-27: patched: Fix released in January 2017 Critical Patch Update

References

Related threats