PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3412 Oracle CVE debrief

CVE-2017-3412 is an Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite's user interface. Oracle and NVD list affected supported releases 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The issue is network-accessible over HTTP, unauthenticated, and requires human interaction. NVD rates it CVSS 3.0 8.2 with confidentiality and integrity impact.

Vendor
Oracle
Product
Advanced Outbound Telephony
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Oracle E-Business Suite administrators, application owners for Advanced Outbound Telephony, security operations teams, and anyone exposing the EBS UI over HTTP.

Technical summary

The vulnerability is in Oracle Advanced Outbound Telephony, a user-interface subcomponent of Oracle E-Business Suite. NVD describes it as easily exploitable by an unauthenticated network attacker using HTTP, but successful attacks depend on human interaction. The published CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, indicating strong confidentiality impact and some integrity impact.

Defensive priority

High

Recommended defensive actions

  • Verify whether any affected Oracle E-Business Suite versions are deployed, especially 12.1.1-12.1.3 and 12.2.3-12.2.6.
  • Review and apply Oracle's January 2017 CPU guidance referenced in the Oracle advisory link.
  • Reduce exposure of the EBS UI over HTTP to trusted networks while remediation is pending.
  • Monitor access and application logs for unexpected interaction with Advanced Outbound Telephony and related UI workflows.
  • Assess downstream products and integrations that could inherit impact from this component.

Evidence notes

Based on the CVE record and NVD detail for CVE-2017-3412. The record states affected Oracle Advanced Outbound Telephony versions and the network/HTTP, unauthenticated, user-interaction-required attack conditions. No KEV entry was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-3412 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-3412

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-3412 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3412

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.