PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3399 Oracle CVE debrief

CVE-2017-3399 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite that Oracle/NVD describe as easily exploitable over HTTP by an unauthenticated attacker, but with human interaction required. The reported impact is strongest for confidentiality and integrity: successful attacks can lead to unauthorized access to critical data, full access to Advanced Outbound Telephony-accessible data, and unauthorized update/insert/delete capabilities. Oracle notes that attacks may also significantly affect additional products.

Vendor
Oracle
Product
CVE-2017-3399
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Oracle E-Business Suite administrators, application security teams, and operations teams responsible for Advanced Outbound Telephony—especially where versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, or 12.2.6 are in use.

Technical summary

NVD lists the CVSS v3.0 vector as AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, indicating a network-accessible flaw with low attack complexity, no privileges required, and a user-interaction requirement. The affected CPEs are Oracle Advanced Outbound Telephony versions 12.1.1 through 12.2.6 as enumerated in the NVD record. The issue is tied to the User Interface subcomponent of Oracle Advanced Outbound Telephony.

Defensive priority

High

Recommended defensive actions

  • Inventory Oracle E-Business Suite deployments to confirm whether Advanced Outbound Telephony versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, or 12.2.6 are present.
  • Review Oracle's January 2017 security advisory for the vendor remediation associated with this CVE and apply the relevant fix for affected systems.
  • Restrict network exposure to the application where possible, especially HTTP access from untrusted networks.
  • Monitor for suspicious user-interaction flows and unauthorized data-access or data-modification activity in the affected component.
  • Prioritize patch validation and post-remediation verification in production environments handling sensitive Oracle E-Business Suite data.

Evidence notes

This debrief is based on the CVE record and NVD metadata supplied in the source corpus. The NVD vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, with affected CPEs for Oracle Advanced Outbound Telephony versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. Oracle's advisory reference is identified as a January 2017 critical patch update/vendor advisory, but the advisory contents were not fetched here.

Official resources

CVE published on 2017-01-27T22:59:06.913Z. NVD last modified the record on 2026-05-13T00:24:29.033Z.