PatchSiren cyber security CVE debrief
CVE-2017-3279 Oracle CVE debrief
CVE-2017-3279 affects Oracle Leads Management in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3. NVD describes it as an easily exploitable issue reachable over HTTP by an unauthenticated network attacker, but successful attacks require human interaction from someone other than the attacker. The impact is primarily on confidentiality and integrity, with potential unauthorized access to critical data or complete access to Oracle Leads Management-accessible data, plus unauthorized update/insert/delete of some accessible data. The published CVSS v3.0 score is 8.2 (High).
- Vendor
- Oracle
- Product
- Leads Management
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Oracle E-Business Suite administrators, application owners, security teams, and incident responders responsible for Oracle Leads Management deployments, especially versions 12.1.1/12.1.2/12.1.3 exposed to user access over HTTP.
Technical summary
NVD lists CVE-2017-3279 as a vulnerability in the Oracle Leads Management user interface component. The CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, indicating network reachability, no privileges required, and a user-interaction dependency. The affected CPEs are Oracle Leads Management 12.1.1, 12.1.2, and 12.1.3. Reported impacts include unauthorized access to critical data or all Leads Management-accessible data, along with limited integrity impacts through unauthorized modification of some accessible data.
Defensive priority
High
Recommended defensive actions
- Apply Oracle's January 2017 CPU or the vendor fix referenced in the Oracle security advisory for this issue.
- Verify whether Oracle Leads Management 12.1.1, 12.1.2, or 12.1.3 is deployed anywhere in the environment, including legacy or indirectly exposed instances.
- Restrict network exposure to Oracle E-Business Suite interfaces and limit access to trusted users and networks where possible.
- Review authentication, session, and access-control configurations around Leads Management user interaction paths.
- Monitor for suspicious access patterns or unexpected data access and modification within Oracle Leads Management.
- Use the official Oracle advisory and NVD record to confirm remediation guidance and affected product scope.
Evidence notes
All facts in this debrief are derived from the supplied NVD record and its referenced Oracle advisory link. The CVE publication date used here is 2017-01-27T22:59:03.570Z, and the later NVD modification timestamp (2026-05-13T00:24:29.033Z) is not treated as the issue date. No exploit code, reproduction steps, or unsupported remediation details are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3279 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3279
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3279 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3279
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.