Junglewise Threat Intelligence

CVE-2017-3411: Oracle Advanced Outbound Telephony UI vulnerability in E-Business Suite

CVE-2017-3411 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a tool used for managing high-volume outbound call center operations. An attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to the unauthorized disclosure of customer information or the corruption of telephony records.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP. The exploit requires human interaction from a person other than the attacker (UI:R), suggesting a Cross-Site Scripting (XSS) or similar UI-based injection flaw. A successful exploit has a 'Changed' scope (S:C), meaning the impact can extend beyond the telephony component to other parts of the E-Business Suite. Attackers can achieve high confidentiality impact and low integrity impact, allowing for the unauthorized reading of critical data and limited modification of records. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update January 2017

References

Related threats