Junglewise Threat Intelligence

CVE-2017-3398: Oracle E-Business Suite vulnerability in Advanced Outbound Telephony UI

CVE-2017-3398 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite, which is used for managing outbound call center operations. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to critical information or the alteration of records within the system.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the immediate component to other parts of the E-Business Suite. Successful attacks can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle E-Business Suite (Advanced Outbound Telephony) 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: NVD publication date
  • 2017-01-27: patched: Oracle Critical Patch Update released

References

Related threats