Vulnerability in Oracle E-Business Suite's Advanced Outbound Telephony Component
CVE-2017-3387

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
27 January 2017

Summary

A security flaw exists in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite that allows unauthenticated attackers with network access via HTTP to exploit the system. Although the vulnerability primarily affects Advanced Outbound Telephony, successful exploitation may lead to unauthorized access to sensitive data and potential manipulation of data within the system. Notably, attacks require human interaction from a third-party user to be effective. Affected versions include 12.1.1 through 12.2.6. As a result, organizations must take preventative measures to secure their systems against potential exploitation.

Affected Version(s)

Advanced Outbound Telephony 12.1.1

Advanced Outbound Telephony 12.1.2

Advanced Outbound Telephony 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.