Junglewise Threat Intelligence

CVE-2017-3413: Oracle Advanced Outbound Telephony vulnerability in User Interface

CVE-2017-3413 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle Advanced Outbound Telephony. Vendors: Oracle.

Executive brief

A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a tool used for managing high-volume outbound call center operations. An attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to customer information or the corruption of telephony records, potentially impacting other integrated business systems.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that can be triggered by an unauthenticated attacker over the network via HTTP. Exploitation requires human interaction from a person other than the attacker (indicated by the UI:R flag), suggesting a cross-site scripting (XSS) or similar client-side injection vulnerability. A successful attack can result in a 'Changed' scope (S:C), meaning the impact can extend beyond the telephony component to other parts of the E-Business Suite. Attackers can achieve high confidentiality impact (unauthorized access to all data) and low integrity impact (unauthorized update/delete of some data). Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: advisory: Initial disclosure by Oracle
  • 2017-01-27: patched: Fix released in Oracle Critical Patch Update

References

Related threats