Executive brief
A vulnerability in the Oracle E-Business Suite's Advanced Outbound Telephony component could allow an unauthorized attacker to access or modify sensitive business data. This component is typically used for managing outbound customer communications and sales calls. An exploit requires a legitimate user to interact with a malicious link or page, which could then lead to a significant breach of data confidentiality and integrity across the system.
Technical details
This vulnerability exists in the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is classified as an 'easily exploitable' flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The attack requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the immediate component to other parts of the E-Business Suite. Successful exploitation can result in unauthorized high-impact access to critical data and low-impact unauthorized modification (update, insert, or delete) of data. The vulnerability affects versions 12.1.1 through 12.2.6 and was addressed in the Oracle January 2017 Critical Patch Update.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update