Executive brief
A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the Oracle E-Business Suite used for managing high-volume outbound communications. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to customer information or the corruption of telephony records.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation requires human interaction from a person other than the attacker (User Interaction: Required). The vulnerability has a 'Changed Scope' impact, meaning a successful attack can impact additional products beyond the telephony component itself. It primarily affects confidentiality (High) and integrity (Low), allowing for unauthorized reading, updating, or deleting of data. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Oracle January 2017 Critical Patch Update released