PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3380 Oracle CVE debrief

CVE-2017-3380 is an Oracle Advanced Outbound Telephony user interface vulnerability in Oracle E-Business Suite. According to the NVD record, it is network-reachable over HTTP, does not require authentication, and does require human interaction. Oracle lists affected supported versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The NVD CVSS v3.0 vector is 8.2 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N), reflecting the potential for significant confidentiality and integrity impact.

Vendor
Oracle
Product
Advanced Outbound Telephony
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Oracle E-Business Suite administrators, application owners, and security teams responsible for Advanced Outbound Telephony UI deployments in the affected versions.

Technical summary

The NVD entry describes an Oracle Advanced Outbound Telephony subcomponent issue exposed via HTTP to unauthenticated attackers. Exploitation requires a human interaction step, but successful attacks can lead to unauthorized access to sensitive data and unauthorized modification of some accessible data. The affected CPEs listed by NVD cover Oracle Advanced Outbound Telephony versions 12.1.1, 12.1.2, 12.1.3, and 12.2.3 through 12.2.6.

Defensive priority

High

Recommended defensive actions

  • Confirm whether any Oracle E-Business Suite instances use Advanced Outbound Telephony in the affected versions listed by NVD.
  • Review and apply Oracle's January 2017 Critical Patch Update guidance referenced by NVD for CVE-2017-3380.
  • Restrict network exposure to the affected HTTP-accessible user interface to trusted users and segments only.
  • Monitor logs for unexpected access patterns or unusual UI activity related to Advanced Outbound Telephony.
  • Reduce reliance on exposed workflows where human interaction could enable exploitation, and provide user awareness where appropriate.

Evidence notes

Source grounding comes from the NVD record for CVE-2017-3380, which lists the affected Oracle Advanced Outbound Telephony versions, the CVSS v3.0 vector, and the HTTP/network + unauthenticated + user-interaction characteristics. Oracle's January 2017 CPU advisory is cited in the NVD references as the vendor patch advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-3380 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-3380

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-3380 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3380

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.