Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:ORACLE:EBUIS-SUITE-CAL-XSS

Severity

Minor

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Oracle E-Business Suite Advanced Outbound Telephony Calendar Cross-Site Scripting

Release Date

2020/06/04

Update Number

3287

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Oracle E-Business Suite Advanced Outbound Telephony Calendar Cross-Site Scripting


This signature detects attempts to exploit a known cross-site scripting vulnerability against E-Business Suite Advanced Outbound Telephony Calendar. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Calendar). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

Affected Products

  • Oracle advanced_outbound_telephony 12.1.1
  • Oracle advanced_outbound_telephony 12.1.2
  • Oracle advanced_outbound_telephony 12.1.3

References

  • CVE: CVE-2020-2856
  • CVE: CVE-2020-2854
  • CVE: CVE-2020-2871
  • CVE: CVE-2020-2852
  • URL: https://www.oracle.com/security-alerts/cpuapr2020.html#appendixe

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out