Executive brief
A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the E-Business Suite used for managing high-volume outbound communications. An attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to critical information or the corruption of telephony records, potentially impacting other integrated business systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is classified as an 'easily exploitable' flaw that can be triggered by an unauthenticated attacker over the network via HTTP. The exploit requires human interaction from a person other than the attacker (UI:R) and results in a Scope change (S:C), indicating that the impact can extend beyond the immediate component to other parts of the E-Business Suite. Successful exploitation allows for unauthorized high-impact confidentiality breaches and low-impact integrity violations, such as reading, updating, or deleting sensitive data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-27: patched: Oracle released fixes in the January 2017 Critical Patch Update