Executive brief
A vulnerability in the Oracle E-Business Suite's Advanced Outbound Telephony component could allow an unauthorized person to access or modify sensitive business data. This component is used by organizations to manage high-volume outbound calling and customer interactions. An attacker could gain full access to telephony data or impact connected systems, though the attack requires a legitimate user to perform a specific action, such as clicking a malicious link.
Technical details
This vulnerability exists in the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector (HTTP) that requires human interaction from a person other than the attacker (UI:R). The vulnerability has a 'Changed' scope (S:C), meaning a successful exploit can impact components beyond the immediate telephony module. Attackers can achieve unauthorized access to all accessible data or perform unauthorized updates, inserts, or deletes on a subset of data. The issue affects versions 12.1.1 through 12.2.6 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-27: patched: Oracle released the January 2017 Critical Patch Update