Oracle E-Business Suite Telephony Component Vulnerability
CVE-2017-3381

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
27 January 2017

Summary

The vulnerability in Oracle Advanced Outbound Telephony within Oracle E-Business Suite allows unauthenticated attackers with network access to exploit the system via HTTP. While the vulnerability itself resides in the telephony component, successful attacks could lead to unauthorized access to critical data and operations, necessitating human interaction to trigger the exploit. Compromised systems may face unauthorized updates, data deletion, or data manipulation, significantly endangering the integrity and confidentiality of the stored information. Organizations using the affected versions should prioritize remediation and enhance their security posture to mitigate potential risks.

Affected Version(s)

Advanced Outbound Telephony 12.1.1

Advanced Outbound Telephony 12.1.2

Advanced Outbound Telephony 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.