Executive brief
A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the E-Business Suite used for managing high-volume outbound communications. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to critical information or the alteration of records within the telephony system and connected business applications.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation requires human interaction from a person other than the attacker (UI:R), suggesting a Cross-Site Scripting (XSS) or similar request forgery class of vulnerability. A successful attack can result in unauthorized access to critical data (Confidentiality) and unauthorized update, insert, or delete access to some data (Integrity). Notably, the vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate telephony module. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Addressed in Oracle January 2017 Critical Patch Update