PatchSiren cyber security CVE debrief
CVE-2017-3406 Oracle CVE debrief
CVE-2017-3406 is a HIGH-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. It is network-reachable over HTTP, requires no attacker privileges, but does require user interaction. Oracle’s advisory and NVD indicate affected supported versions include 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. Successful exploitation can expose critical data and may allow unauthorized data modification in the affected component.
- Vendor
- Oracle
- Product
- Advanced Outbound Telephony
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Oracle E-Business Suite administrators, application security teams, and operations teams responsible for Oracle Advanced Outbound Telephony deployments, especially where the user interface is exposed to network-accessible users or external traffic.
Technical summary
NVD lists CVSS v3.0 AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N for CVE-2017-3406. The issue is in the User Interface subcomponent of Oracle Advanced Outbound Telephony. Impact is primarily confidentiality, with some integrity impact, and the attack path is unauthenticated but depends on a separate person interacting with the vulnerable interface.
Defensive priority
High
Recommended defensive actions
- Confirm whether Oracle Advanced Outbound Telephony is deployed in any Oracle E-Business Suite environment.
- Check whether affected supported versions listed by NVD are in use: 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.
- Apply Oracle’s vendor remediation referenced in the January 2017 CPU advisory where applicable.
- Restrict exposure of the component to trusted users and networks, especially any HTTP-accessible paths.
- Review access controls and logging for suspicious interaction with the Advanced Outbound Telephony user interface.
- Treat the issue as priority if the component is internet-facing or used by broad internal user populations.
Evidence notes
This debrief uses the CVE record published on 2017-01-27 and the NVD record modified on 2026-05-13. The description, affected versions, CVSS vector, and vendor reference are taken from the supplied source corpus only. No exploit steps or unsupported assumptions are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3406 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3406
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3406 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3406
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.