Junglewise Threat Intelligence

CVE-2017-3408: Oracle Advanced Outbound Telephony unauthorized data access in UI

CVE-2017-3408 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite, which is used by organizations to manage high-volume outbound calling and customer contact operations. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify records within the system. Successful exploitation requires a legitimate user to interact with a malicious link or page, and the impact may extend beyond the telephony module to other integrated Oracle products.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is classified as easily exploitable via the network using HTTP without requiring authentication. The attack requires human interaction (User Interaction: Required) from a person other than the attacker, suggesting a Cross-Site Scripting (XSS) or similar UI-based injection flaw. Successful exploitation allows an attacker to achieve high confidentiality impact and partial integrity impact, with the potential to affect components beyond the initial scope (Scope: Changed). Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update (CPU) released

References

Related threats