PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3443 Oracle CVE debrief

CVE-2017-3443 is a high-severity Oracle E-Business Suite Common Applications vulnerability in the User Interface subcomponent. Oracle and NVD describe it as network-reachable over HTTP, unauthenticated, and requiring human interaction, with successful attacks capable of exposing critical data and allowing unauthorized data modification in affected Common Applications environments. The issue affects supported versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.

Vendor
Oracle
Product
Common Applications
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Oracle E-Business Suite administrators, application owners, and security teams responsible for Common Applications deployments should prioritize this advisory, especially where internet-facing access, user interaction through the UI, or sensitive business data is involved.

Technical summary

NVD lists the vulnerability with CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N, indicating remote network attackability, no privileges required, and a user-interaction requirement. The affected product scope is Oracle Common Applications in Oracle E-Business Suite, specifically the User Interface subcomponent. Oracle’s advisory referenced by NVD is the primary vendor source for remediation. The vulnerability is not described in the supplied corpus with a CWE beyond NVD-CWE-noinfo, so no more specific weakness characterization should be assumed.

Defensive priority

High. The combination of unauthenticated network exposure, required user interaction, and high confidentiality impact makes this a strong candidate for expedited patching and exposure reduction.

Recommended defensive actions

  • Review Oracle CPU January 2017 advisory for the applicable fix for your E-Business Suite release.
  • Confirm whether any affected Common Applications versions are deployed: 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, or 12.2.6.
  • Prioritize patching systems that are reachable over HTTP or support user-driven UI workflows.
  • Reduce exposure by limiting network access to E-Business Suite interfaces where possible until remediation is complete.
  • Validate that change management, regression testing, and post-patch verification are completed for the affected application stack.
  • Monitor for abnormal UI-driven access patterns or unexpected data access around the affected Common Applications environment.

Evidence notes

All statements are grounded in the supplied NVD record and its Oracle vendor advisory reference. The CVE publication date used here is 2017-01-27T22:59:08.320Z, per the provided timeline. The supplied record states that successful attacks can lead to unauthorized access to critical data or complete access to accessible Common Applications data, as well as unauthorized update/insert/delete access to some accessible data. The record also indicates that the vulnerability requires human interaction and affects supported Oracle E-Business Suite Common Applications versions listed in the CPE criteria.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-3443 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-3443

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-3443 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3443

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.