Executive brief
A vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite, which manages automated customer outreach and call center operations. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to the unauthorized disclosure of customer information or the corruption of telephony records, potentially impacting other integrated business systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an unauthenticated, network-based attack (via HTTP) that requires human interaction from a victim (User Interaction: Required). The vulnerability has a 'Changed' scope, meaning an exploit can impact components beyond the immediate telephony module. Successful exploitation can result in unauthorized read access to all accessible data (Confidentiality: High) and unauthorized update, insert, or delete access to some data (Integrity: Low). Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-27: patched: Addressed in Oracle January 2017 Critical Patch Update