Executive brief
A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the E-Business Suite used for managing high-volume outbound communications. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to critical customer information or the corruption of telephony records.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires user interaction (UI:R) and results in a scope change (S:C). The flaw allows an attacker to gain unauthorized access to critical data or perform unauthorized updates, inserts, or deletes on a subset of accessible data. While the root cause is not explicitly detailed in the advisory, the requirement for user interaction and the 'Scope: Changed' metric often suggest a Cross-Site Scripting (XSS) or similar web-based injection vulnerability. Patches were released as part of the Oracle Critical Patch Update (CPU) in January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial publication by Oracle and NVD
- 2017-01-27: patched: Fixes released in January 2017 Critical Patch Update