Executive brief
A vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite, which manages automated customer outreach and call center operations. An unauthenticated attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to interact with a malicious link or page, potentially allowing the attacker to compromise the telephony system and impact connected business applications.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector (HTTP) that requires user interaction (UI:R) to succeed. The vulnerability has a 'Changed Scope' (S:C), meaning an exploit can impact components beyond the immediate telephony module. Attackers can achieve unauthorized access to critical data (Confidentiality: High) and perform unauthorized updates or deletions of some data (Integrity: Low). Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory