PatchSiren cyber security CVE debrief
CVE-2017-3399 Oracle CVE debrief
CVE-2017-3399 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite that Oracle/NVD describe as easily exploitable over HTTP by an unauthenticated attacker, but with human interaction required. The reported impact is strongest for confidentiality and integrity: successful attacks can lead to unauthorized access to critical data, full access to Advanced Outbound Telephony-accessible data, and unauthorized update/insert/delete capabilities. Oracle notes that attacks may also significantly affect additional products.
- Vendor
- Oracle
- Product
- CVE-2017-3399
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Oracle E-Business Suite administrators, application security teams, and operations teams responsible for Advanced Outbound Telephony—especially where versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, or 12.2.6 are in use.
Technical summary
NVD lists the CVSS v3.0 vector as AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, indicating a network-accessible flaw with low attack complexity, no privileges required, and a user-interaction requirement. The affected CPEs are Oracle Advanced Outbound Telephony versions 12.1.1 through 12.2.6 as enumerated in the NVD record. The issue is tied to the User Interface subcomponent of Oracle Advanced Outbound Telephony.
Defensive priority
High
Recommended defensive actions
- Inventory Oracle E-Business Suite deployments to confirm whether Advanced Outbound Telephony versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, or 12.2.6 are present.
- Review Oracle's January 2017 security advisory for the vendor remediation associated with this CVE and apply the relevant fix for affected systems.
- Restrict network exposure to the application where possible, especially HTTP access from untrusted networks.
- Monitor for suspicious user-interaction flows and unauthorized data-access or data-modification activity in the affected component.
- Prioritize patch validation and post-remediation verification in production environments handling sensitive Oracle E-Business Suite data.
Evidence notes
This debrief is based on the CVE record and NVD metadata supplied in the source corpus. The NVD vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, with affected CPEs for Oracle Advanced Outbound Telephony versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. Oracle's advisory reference is identified as a January 2017 critical patch update/vendor advisory, but the advisory contents were not fetched here.
Official resources
-
CVE-2017-3399 CVE record
CVE.org
-
CVE-2017-3399 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
- Source reference
CVE published on 2017-01-27T22:59:06.913Z. NVD last modified the record on 2026-05-13T00:24:29.033Z.