PatchSiren cyber security CVE debrief
CVE-2017-3412 Oracle CVE debrief
CVE-2017-3412 is an Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite's user interface. Oracle and NVD list affected supported releases 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The issue is network-accessible over HTTP, unauthenticated, and requires human interaction. NVD rates it CVSS 3.0 8.2 with confidentiality and integrity impact.
- Vendor
- Oracle
- Product
- Advanced Outbound Telephony
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Oracle E-Business Suite administrators, application owners for Advanced Outbound Telephony, security operations teams, and anyone exposing the EBS UI over HTTP.
Technical summary
The vulnerability is in Oracle Advanced Outbound Telephony, a user-interface subcomponent of Oracle E-Business Suite. NVD describes it as easily exploitable by an unauthenticated network attacker using HTTP, but successful attacks depend on human interaction. The published CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, indicating strong confidentiality impact and some integrity impact.
Defensive priority
High
Recommended defensive actions
- Verify whether any affected Oracle E-Business Suite versions are deployed, especially 12.1.1-12.1.3 and 12.2.3-12.2.6.
- Review and apply Oracle's January 2017 CPU guidance referenced in the Oracle advisory link.
- Reduce exposure of the EBS UI over HTTP to trusted networks while remediation is pending.
- Monitor access and application logs for unexpected interaction with Advanced Outbound Telephony and related UI workflows.
- Assess downstream products and integrations that could inherit impact from this component.
Evidence notes
Based on the CVE record and NVD detail for CVE-2017-3412. The record states affected Oracle Advanced Outbound Telephony versions and the network/HTTP, unauthenticated, user-interaction-required attack conditions. No KEV entry was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3412 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3412
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3412 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3412
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.