Junglewise Threat Intelligence

CVE-2017-3399: Oracle Advanced Outbound Telephony UI vulnerability in E-Business Suite

CVE-2017-3399 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle E-Business Suite's Advanced Outbound Telephony component, which manages automated customer outreach and call center operations. An attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to customer information or the corruption of telephony records.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (User Interaction: Required) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning a successful exploit can impact components beyond the immediate telephony module. Attackers can achieve unauthorized access to critical data (Confidentiality: High) and perform unauthorized updates or deletions of some data (Integrity: Low). The issue is present in versions 12.1.1 through 12.2.6 and was addressed in the Oracle January 2017 Critical Patch Update.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-27: patched: Addressed in Oracle Critical Patch Update January 2017

References

Related threats