Junglewise Threat Intelligence

CVE-2017-3412: Oracle Advanced Outbound Telephony vulnerability in User Interface

CVE-2017-3412 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle E-Business Suite's Advanced Outbound Telephony component, which manages automated customer outreach and call center operations. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to customer information or the corruption of telephony records.

Technical details

A vulnerability in the User Interface subcomponent of Oracle Advanced Outbound Telephony (part of Oracle E-Business Suite) allows an unauthenticated remote attacker to compromise the application. The attack is delivered via HTTP and requires human interaction from a person other than the attacker (UI:R), suggesting a Cross-Site Scripting (XSS) or similar client-side injection flaw. Successful exploitation can result in a 'Changed' scope (S:C), meaning the impact can extend beyond the telephony component to other parts of the E-Business Suite. Attackers can achieve unauthorized access to critical data or complete access to all accessible data, as well as unauthorized update, insert, or delete capabilities for some data. Affected versions include 12.1.1-12.1.3 and 12.2.3-12.2.6.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory

References

Related threats