Junglewise Threat Intelligence

CVE-2017-3406: Oracle Advanced Outbound Telephony unauthorized data access in User Interface

CVE-2017-3406 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a tool used for managing automated customer outreach. An attacker could trick a legitimate user into performing an action that grants the attacker unauthorized access to sensitive business data. This could lead to the theft of customer information or unauthorized changes to telephony records, potentially impacting other connected business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that can be triggered by an unauthenticated attacker over the network via HTTP. Exploitation requires human interaction from a person other than the attacker (e.g., a Cross-Site Scripting or similar UI-based attack). A successful exploit allows the attacker to gain unauthorized access to critical data or complete access to all accessible data, as well as the ability to update, insert, or delete certain records. The vulnerability has a 'Changed' scope, meaning it may impact products beyond the initial component. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats