Executive brief
A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the E-Business Suite used for managing high-volume outbound communications. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to a significant breach of confidentiality and data integrity across the telephony system and potentially connected business applications.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an unauthenticated, network-based attack (via HTTP) that requires human interaction from a person other than the attacker (UI:R). The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate telephony module. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update