Junglewise Threat Intelligence

CVE-2017-3409: Oracle Advanced Outbound Telephony data compromise in User Interface

CVE-2017-3409 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A security vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite, which is used by organizations to manage high-volume outbound communications. An attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify records within the system. This could lead to significant data breaches or the disruption of automated telephony operations, potentially impacting other integrated business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP. Exploitation requires human interaction from a user other than the attacker (UI:R), suggesting a vulnerability class such as Cross-Site Scripting (XSS) or a similar UI-based injection. A successful exploit has a 'Changed' scope (S:C), meaning it can impact components beyond the immediate telephony module. The primary impact is on Confidentiality (High) and Integrity (Low), allowing for unauthorized viewing of all accessible data and limited modification of records.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial publication of the vulnerability advisory.
  • 2017-01-27: patched: Oracle released patches as part of the January 2017 Critical Patch Update.

References

Related threats