Executive brief
A vulnerability exists in the Oracle E-Business Suite component used for managing outbound call center operations. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to the unauthorized disclosure of customer information or the corruption of telephony records.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (User Interaction: Required) from someone other than the attacker. The vulnerability has a 'Changed' scope, meaning an exploit can impact components beyond the immediate software. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The issue is addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published