Executive brief
A vulnerability exists in the user interface of Oracle Advanced Outbound Telephony, a component of the Oracle E-Business Suite used for managing outbound call center operations. An attacker could trick a user into performing an action that allows the attacker to gain unauthorized access to sensitive business data or modify records. This could lead to the exposure of customer information or the corruption of telephony data, potentially impacting other integrated Oracle products.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation requires human interaction from a person other than the attacker (User Interaction: Required). The vulnerability has a 'Changed' scope, meaning a successful attack can impact products beyond the immediate component. Impact includes high confidentiality loss (unauthorized access to all accessible data) and partial integrity loss (unauthorized update, insert, or delete access to some data). The vulnerability was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published