Executive brief
A vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite, which is used by organizations to manage high-volume outbound calling and customer interactions. An attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify records, potentially leading to data theft or operational disruption. Successful exploitation requires a legitimate user to interact with a malicious link or page, and the impact may extend beyond the telephony system to other connected Oracle products.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an unauthenticated, network-based attack via HTTP that requires human interaction (UI:R) from a person other than the attacker. The vulnerability has a 'Changed' scope (S:C), meaning a successful exploit can impact components beyond the immediate telephony module. Attackers can achieve high confidentiality impact, gaining access to all accessible data, and partial integrity impact through unauthorized updates or deletions. The issue is addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published