PatchSiren

Oracle CVE debriefs · Page 21

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3398

CVE-2017-3398 is a high-severity Oracle vulnerability in the Advanced Outbound Telephony component of Oracle E-Business Suite. Oracle’s advisory and NVD describe it as easily exploitable over HTTP by an unauthenticated network attacker, but successful exploitation requires human interaction from a person other than the attacker. The issue can expose critical data and may allow unauthorized update, insert, [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3397

CVE-2017-3397 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. Oracle and NVD describe it as easily exploitable over HTTP, requiring no attacker privileges but needing human interaction from another person. The affected versions listed in the record are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. Successful exploitation can expose critical dat [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3396

CVE-2017-3396 is a high-severity Oracle vulnerability in the Advanced Outbound Telephony user interface component of Oracle E-Business Suite. Oracle’s advisory and the NVD record describe an unauthenticated, network-reachable issue over HTTP that requires human interaction and can expose or alter sensitive data in affected deployments.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3395

CVE-2017-3395 is a HIGH-severity Oracle vulnerability in the Advanced Outbound Telephony user interface for Oracle E-Business Suite. Oracle describes it as easily exploitable over HTTP by an unauthenticated attacker, but with required human interaction. Oracle’s advisory says successful attacks can expose sensitive data and allow some unauthorized data changes, and that impacts may extend beyond the affec [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3394

CVE-2017-3394 affects the Oracle Advanced Outbound Telephony component in Oracle E-Business Suite, specifically the User Interface subcomponent. Oracle and NVD list affected supported versions as 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The issue is network reachable over HTTP, does not require authentication, and has a high CVSS v3.0 score of 8.2. Oracle’s description also notes that s [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3392

CVE-2017-3392 is a high-severity vulnerability in Oracle E-Business Suite’s Advanced Outbound Telephony component (User Interface). Oracle/NVD list affected versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The issue is described as easily exploitable over HTTP by an unauthenticated network attacker, but successful attacks require human interaction from someone other than the attacker. [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3391

CVE-2017-3391 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. According to the CVE record and NVD, an unauthenticated attacker can reach the issue over HTTP, but exploitation requires human interaction from another person. Successful attacks can lead to unauthorized access to critical data and unauthorized update, insert, or delete access to some accessible [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3390

CVE-2017-3390 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite. NVD describes it as a network-accessible HTTP vulnerability that does not require authentication, but does require human interaction. If successfully exploited, it can lead to unauthorized access to critical data and to some unauthorized update, insert, or delete capability for data handled by Advanced Ou [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3389

CVE-2017-3389 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite. According to NVD, the flaw is network-reachable over HTTP, requires no authentication, but does require human interaction. Successful exploitation can expose sensitive data and allow unauthorized changes to data handled by the component. Oracle and NVD list affected versions including 12.1.1 through 12.2.6.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3388

CVE-2017-3388 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. Oracle and NVD describe it as easily exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from someone other than the attacker. If exploited, it can expose critical data and permit unauthorized data changes in affected Advanced Outbound Telephony data.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3387

CVE-2017-3387 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite. Oracle and NVD describe it as an easily exploitable network vulnerability that can be reached over HTTP and requires human interaction, with potential impact to confidentiality and integrity. Affected versions listed in the record are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3386

CVE-2017-3386 is a high-severity Oracle vulnerability affecting the Advanced Outbound Telephony component of Oracle E-Business Suite. According to the CVE record, an unauthenticated attacker with network access via HTTP can exploit the issue, but successful attacks require human interaction from another person. Oracle/NVD indicate the impact can include unauthorized access to critical data and unauthorize [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3385

CVE-2017-3385 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite, published on 2017-01-27. Oracle identifies it as easily exploitable by an unauthenticated attacker with network access via HTTP, but successful exploitation requires human interaction. If exploited, it can expose critical data and allow unauthorized modification of some Oracle Advanced Outbound Telephony- [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3384

CVE-2017-3384 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite that Oracle and NVD describe as easily exploitable over HTTP by an unauthenticated attacker. The issue requires user interaction and can expose or modify sensitive telephony-accessible data. Affected versions listed in the source data are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3383

CVE-2017-3383 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. According to the CVE record, an unauthenticated attacker with network access via HTTP can exploit the issue, but successful attacks require human interaction from someone other than the attacker. Oracle’s affected versions listed in the record are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, an [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3382

CVE-2017-3382 is a High-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite’s User Interface component. Oracle and NVD describe it as remotely reachable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction. The documented impact includes unauthorized access to critical data and unauthorized modification of some accessible data, w [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3381

CVE-2017-3381 is a high-severity Oracle E-Business Suite issue in the Advanced Outbound Telephony user interface. According to NVD, it is network accessible over HTTP, does not require privileges, and can be triggered only with user interaction. The published impact includes unauthorized access to sensitive data and unauthorized modification of some accessible data. Oracle’s January 2017 CPU is the refere [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3380

CVE-2017-3380 is an Oracle Advanced Outbound Telephony user interface vulnerability in Oracle E-Business Suite. According to the NVD record, it is network-reachable over HTTP, does not require authentication, and does require human interaction. Oracle lists affected supported versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The NVD CVSS v3.0 vector is 8.2 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3379

CVE-2017-3379 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite. According to NVD, it affects supported versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The vulnerability is described as easily exploitable over HTTP by an unauthenticated attacker, but successful attacks require human interaction from someone other than the attacker. Impact includes [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3378

CVE-2017-3378 is a high-severity Oracle E-Business Suite issue in the Advanced Outbound Telephony user interface. Oracle and NVD describe it as easily exploitable over HTTP by an unauthenticated network attacker, but successful exploitation requires human interaction. If abused, it can expose critical data and allow unauthorized data changes in affected Advanced Outbound Telephony environments.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3377

CVE-2017-3377 is a high-severity Oracle Advanced Outbound Telephony issue in Oracle E-Business Suite. NVD describes it as easily exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from someone other than the attacker. Oracle’s affected versions listed in NVD are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The recorded impact include [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3376

CVE-2017-3376 is a vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite, specifically the User Interface subcomponent. Oracle and NVD describe it as easily exploitable over HTTP by an unauthenticated attacker, but successful attacks require human interaction by someone other than the attacker. The impact is primarily on confidentiality and integrity, with potential [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3375

CVE-2017-3375 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. The supplied NVD and Oracle references describe it as remotely reachable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from someone other than the attacker. Impact includes unauthorized access to critical data and unauthorized update, insert, or d [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3374

CVE-2017-3374 is a high-severity Oracle Advanced Outbound Telephony vulnerability in Oracle E-Business Suite. Oracle and NVD describe it as network-exploitable over HTTP, requiring no attacker authentication but requiring human interaction from another person. Successful attacks can expose sensitive data and enable limited data modification within the affected component.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3373

CVE-2017-3373 is a high-severity vulnerability in Oracle Advanced Outbound Telephony, a component of Oracle E-Business Suite. Oracle and NVD indicate that supported versions 12.1.1 through 12.2.6 were affected. The issue is network-accessible over HTTP, does not require authentication, and needs human interaction from someone other than the attacker. Successful exploitation could expose critical data and [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3372

CVE-2017-3372 is a high-severity vulnerability in Oracle Interaction Blending, a user-interface subcomponent of Oracle E-Business Suite. The supplied NVD record lists affected versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. It is network-reachable over HTTP, does not require authentication, but does require human interaction from someone other than the attacker. NVD rates the issue CV [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3371

CVE-2017-3371 affects Oracle iSupport in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3. According to the supplied NVD record, the issue is exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction. The expected impact is serious: unauthorized access to critical data, full access to iSupport-accessible data, and unauthorized update/insert/delete opera [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3370

CVE-2017-3370 is a high-severity Oracle iSupport issue in Oracle E-Business Suite. Oracle and NVD list affected supported versions as 12.1.1, 12.1.2, and 12.1.3. The vulnerability is network-accessible over HTTP, does not require authentication, and can lead to unauthorized access to sensitive Oracle iSupport data and unauthorized modification of some accessible data. Successful exploitation requires huma [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3369

CVE-2017-3369 is a high-severity Oracle E-Business Suite iSupport vulnerability affecting versions 12.1.1, 12.1.2, and 12.1.3. Oracle and NVD describe it as network-reachable over HTTP, unauthenticated, and requiring human interaction, with potential impact to confidentiality and integrity of iSupport data.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3368

CVE-2017-3368 is a high-severity Oracle iStore vulnerability in Oracle E-Business Suite’s Address Book subcomponent. Oracle’s description says it is easily exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from a person other than the attacker. The impact can include unauthorized access to critical data and unauthorized update, insert, or delete a [truncated]