Junglewise Threat Intelligence

CVE-2017-3405: Oracle Advanced Outbound Telephony unauthorized data access in User Interface

CVE-2017-3405 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle E-Business Suite's Advanced Outbound Telephony component could allow an unauthorized person to access or modify sensitive business data. This component is typically used by organizations to manage high-volume outbound calling and customer outreach. An attacker could exploit this flaw by tricking a legitimate user into performing an action, potentially leading to the theft of customer information or unauthorized changes to business records.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction from a person other than the attacker (UI:R). The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate telephony module. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized write, update, or delete access to a subset of that data. The issue is addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update

References

Related threats