These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2017-3428 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite’s User Interface subcomponent. According to the NVD and Oracle’s referenced advisory, it is network reachable over HTTP, requires no attacker authentication, and can have significant confidentiality and integrity impact. The CVSS v3.0 vector indicates user interaction is required and the scope changes, [truncated]
CVE-2017-3427 is a high-severity vulnerability in Oracle E-Business Suite’s One-to-One Fulfillment component. According to the CVE record, an unauthenticated attacker with network access over HTTP can exploit the issue, but successful attacks require human interaction. Oracle and NVD list affected supported versions from 12.1.1 through 12.2.6. The described impact includes unauthorized access to critical [truncated]
CVE-2017-3426 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite. According to the CVE and NVD records, it is reachable over the network via HTTP, does not require attacker authentication, and can lead to unauthorized access to critical data and some data modification. Exploitation does require human interaction from someone other than the attacker, but the potential [truncated]
CVE-2017-3425 is a HIGH-severity Oracle vulnerability in the One-to-One Fulfillment component of Oracle E-Business Suite, specifically the User Interface subcomponent. NVD rates it 8.2 (CVSS v3.0) and describes it as network-reachable over HTTP, unauthenticated, but requiring human interaction. Successful attacks can expose critical data and allow unauthorized modification of some accessible data.
CVE-2017-3424 is a HIGH-severity Oracle vulnerability in the One-to-One Fulfillment component of Oracle E-Business Suite. NVD describes it as easily exploitable over HTTP by an unauthenticated attacker, but with a user-interaction requirement. Successful attacks can expose critical data and allow unauthorized changes to some One-to-One Fulfillment data.
CVE-2017-3423 is a high-severity Oracle One-to-One Fulfillment flaw in Oracle E-Business Suite’s User Interface subcomponent. Oracle and NVD describe it as remotely reachable over HTTP, unauthenticated, and requiring human interaction, with potential impact to confidentiality and integrity of accessible data. Because it affects a business-critical ERP component and may have broader product impact, it shou [truncated]
CVE-2017-3422 is a high-severity vulnerability in Oracle E-Business Suite’s One-to-One Fulfillment component (User Interface). Oracle’s published description says it is easily exploitable by an unauthenticated network attacker via HTTP, but successful attacks require human interaction. If abused, it can expose critical data and allow unauthorized changes to some accessible data.
CVE-2017-3421 is a high-severity Oracle One-to-One Fulfillment vulnerability in Oracle E-Business Suite. NVD describes it as an easily exploitable issue over HTTP that can be used by an unauthenticated network attacker, but successful attacks require human interaction. The reported impact includes unauthorized access to critical data and unauthorized modification of some accessible data.
CVE-2017-3420 is a high-severity vulnerability in Oracle CRM Technical Foundation, a component of Oracle E-Business Suite, affecting version 12.1.3. NVD describes it as easily exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from someone other than the attacker. Oracle and NVD rate the issue as materially affecting confidentiality and integrity, [truncated]
CVE-2017-3419 is a high-severity vulnerability in Oracle E-Business Suite’s CRM Technical Foundation (User Interface subcomponent) affecting version 12.1.3. Oracle’s description says it is easily exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from someone other than the attacker. Impact can include unauthorized access to critical data, complete [truncated]
CVE-2017-3418 is a high-severity Oracle CRM Technical Foundation issue in Oracle E-Business Suite 12.1.3. NVD describes it as an easily exploitable vulnerability reachable over HTTP by an unauthenticated attacker, with successful attacks requiring human interaction from another person. The impact can include unauthorized access to critical data and unauthorized update, insert, or delete access to some dat [truncated]
CVE-2017-3417 is a high-severity Oracle Universal Work Queue vulnerability affecting supported Oracle E-Business Suite releases 12.1.1 through 12.2.6. The published description says an unauthenticated attacker with network access via HTTP can compromise the component, but successful exploitation requires human interaction from someone other than the attacker. The reported impact includes unauthorized acce [truncated]
CVE-2017-3416 is an Oracle Universal Work Queue vulnerability in Oracle E-Business Suite that Oracle and NVD describe as easily exploitable over HTTP by an unauthenticated attacker, with successful attacks requiring human interaction. The reported impact is primarily on confidentiality and integrity, including unauthorized access to critical data and unauthorized update, insert, or delete actions against [truncated]
CVE-2017-3415 is a high-severity Oracle Universal Work Queue issue in Oracle E-Business Suite. According to the supplied NVD record, it affects supported versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. Oracle describes it as easily exploitable by an unauthenticated attacker with network access via HTTP, but successful exploitation requires human interaction. The stated impact includes [truncated]
CVE-2017-3414 is a high-severity Oracle E-Business Suite vulnerability in the Advanced Outbound Telephony user interface. Oracle’s description says an unauthenticated attacker with network access over HTTP can exploit the issue, but successful attacks require human interaction from someone other than the attacker. The affected releases listed by NVD are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and [truncated]
CVE-2017-3413 is a high-severity Oracle vulnerability in the Advanced Outbound Telephony component of Oracle E-Business Suite. Oracle and NVD describe it as remotely reachable over HTTP, requiring no authentication but needing human interaction, with successful exploitation potentially exposing sensitive data and allowing some data modification. Oracle listed affected releases including 12.1.1 through 12. [truncated]
CVE-2017-3412 is an Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite's user interface. Oracle and NVD list affected supported releases 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The issue is network-accessible over HTTP, unauthenticated, and requires human interaction. NVD rates it CVSS 3.0 8.2 with confidentiality and integrity impact.
CVE-2017-3411 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. According to NVD, it is remotely reachable over HTTP, requires no authentication, and does require human interaction. Oracle’s affected versions listed in the record are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. Successful exploitation can expose sensitive data and allow unauthor [truncated]
CVE-2017-3410 is a high-severity Oracle E-Business Suite issue in the Advanced Outbound Telephony user interface. NVD describes it as an easily exploitable, network-reachable HTTP vulnerability that can be triggered by an unauthenticated attacker, but it does require human interaction from someone other than the attacker. Successful exploitation can expose critical data and can also allow unauthorized mod [truncated]
CVE-2017-3409 is a high-severity Oracle E-Business Suite issue in Advanced Outbound Telephony (User Interface) that can be triggered over HTTP by an unauthenticated network attacker, but it also requires human interaction from a person other than the attacker. Oracle’s published impact summary says successful attacks can expose critical data and allow unauthorized changes to some accessible data.
CVE-2017-3408 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. NVD describes it as easily exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction. The issue can expose critical data and allow unauthorized modification of some accessible data, with possible impact beyond the telephony component.
CVE-2017-3407 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite's User Interface subcomponent. Oracle and NVD describe it as remotely reachable over HTTP, unauthenticated, and requiring human interaction from a person other than the attacker. The published impact includes unauthorized access to critical data, broad access to accessible data, and unauthorized data modif [truncated]
CVE-2017-3406 is a HIGH-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. It is network-reachable over HTTP, requires no attacker privileges, but does require user interaction. Oracle’s advisory and NVD indicate affected supported versions include 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. Successful exploitation can expose critical data and may allow u [truncated]
CVE-2017-3405 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. Oracle/NVD describe it as easily exploitable by an unauthenticated attacker with network access via HTTP, but successful exploitation requires human interaction from another person. The impact can include unauthorized access to critical data and unauthorized update, insert, or delete access to som [truncated]
CVE-2017-3404 is an Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite’s user interface component. Oracle and NVD describe it as easily exploitable over HTTP by an unauthenticated network attacker, but successful abuse requires human interaction and can expose or alter sensitive data.
CVE-2017-3403 is a high-severity Oracle vulnerability in the Advanced Outbound Telephony component of Oracle E-Business Suite. Oracle describes it as easily exploitable over HTTP by an unauthenticated network attacker, but successful exploitation requires human interaction from someone other than the attacker. The issue can expose critical data and allow unauthorized data access and some data modification [truncated]
CVE-2017-3402 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. Oracle and NVD describe it as remotely reachable over HTTP, unauthenticated, and requiring human interaction, with potential for unauthorized access to sensitive data and some update/insert/delete capability.
CVE-2017-3401 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite. Oracle and NVD describe it as easily exploitable over HTTP by an unauthenticated attacker, but successful attacks require human interaction from someone other than the attacker. Impact is primarily confidentiality and integrity loss, with potential unauthorized access to critical data or to all Advanced O [truncated]
CVE-2017-3400 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite. Oracle’s description, as reflected in NVD, says the flaw is easily exploitable over HTTP by an unauthenticated network attacker, but successful attacks require human interaction from someone other than the attacker. The published impact includes unauthorized access to critical data, possible complete acce [truncated]
CVE-2017-3399 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite that Oracle/NVD describe as easily exploitable over HTTP by an unauthenticated attacker, but with human interaction required. The reported impact is strongest for confidentiality and integrity: successful attacks can lead to unauthorized access to critical data, full access to Advanced Outbound Telephony-a [truncated]