Unauthorized Access Vulnerability in Oracle E-Business Suite Advanced Outbound Telephony
CVE-2017-3376

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
27 January 2017

What is CVE-2017-3376?

This vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite, allowing an unauthenticated attacker with network access via HTTP to exploit the system. While direct exploitation pertains to the Advanced Outbound Telephony component, the consequences can extend to other integrated products. Successful exploitation requires interaction from a user, yet it can lead to unauthorized access to sensitive data and permits attackers to perform operations like unauthorized updates, inserts, or deletions within the database. This creates significant risks for organizations relying on these systems.

Affected Version(s)

Advanced Outbound Telephony 12.1.1

Advanced Outbound Telephony 12.1.2

Advanced Outbound Telephony 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.