Executive brief
A vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite, which manages automated customer outreach and call center operations. An attacker could trick a user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to a significant breach of customer information or disruption of telephony services.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation requires human interaction from a person other than the attacker (User Interaction: Required). The vulnerability has a 'Changed' scope (S:C), meaning a successful attack can impact additional products beyond the telephony component itself. Attackers can achieve unauthorized access to critical data, complete access to all accessible data, and unauthorized update, insert, or delete capabilities for certain data sets.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed: Initial NVD publication
- 2017-01-27: advisory: Oracle Critical Patch Update published