PatchSiren cyber security CVE debrief
CVE-2017-3430 Oracle CVE debrief
CVE-2017-3430 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite’s User Interface component. Oracle and NVD describe it as network-exploitable over HTTP by an unauthenticated attacker, with successful exploitation requiring human interaction from a person other than the attacker. The documented impact includes unauthorized access to critical data and unauthorized update, insert, or delete access to some accessible data. Oracle published the issue on 2017-01-27.
- Vendor
- Oracle
- Product
- One-To-One Fulfillment
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Oracle E-Business Suite administrators, security teams, and application owners running One-to-One Fulfillment on affected supported releases: 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.
Technical summary
The NVD record maps CVE-2017-3430 to Oracle One-to-One Fulfillment with CVSS v3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, reflecting remote network attackability, no privileges required, and a user-interaction requirement. The affected CPEs listed by NVD are specific Oracle One-to-One Fulfillment versions 12.1.1 through 12.2.6. The issue is associated with confidentiality and integrity impact, not availability impact, and NVD lists CWE as NVD-CWE-noinfo.
Defensive priority
High
Recommended defensive actions
- Verify whether any Oracle E-Business Suite deployments run One-to-One Fulfillment versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, or 12.2.6.
- Review Oracle’s January 2017 security advisory for vendor guidance and patch information.
- Limit exposure of the affected application where possible, especially HTTP access paths to the user interface.
- Monitor for unauthorized data access or unexpected data modification activity in the affected component.
- Prioritize remediation in environments where the application handles sensitive or business-critical data.
Evidence notes
Facts above are drawn from the CVE record, NVD detail, and Oracle advisory reference included in the source corpus. NVD lists the affected Oracle One-to-One Fulfillment versions and the CVSS vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N. Oracle’s advisory reference is CPU Jan 2017, and the NVD record includes references to the Oracle advisory and SecurityFocus BID 95569. No exploit code or unsupported claims are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3430 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3430
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3430 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3430
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.