Junglewise Threat Intelligence

CVE-2017-3404: Oracle Advanced Outbound Telephony UI vulnerability in E-Business Suite

CVE-2017-3404 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite, which manages automated customer outreach and call center operations. An attacker can exploit this flaw to gain unauthorized access to sensitive business data or modify records, potentially disrupting sales and customer service operations. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could then allow the attacker to compromise the system or impact connected business applications.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The exploit requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the immediate component to other parts of the E-Business Suite. Successful exploitation can result in unauthorized high-impact confidentiality breaches and low-impact integrity violations, such as reading, updating, or deleting sensitive data. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle January 2017 Critical Patch Update published

References

Related threats