Executive brief
A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a tool used for managing high-volume outbound calling operations. An attacker could trick a legitimate user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to customer information or the corruption of telephony records, potentially impacting other connected business systems.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is classified as an 'easily exploitable' flaw that can be triggered by an unauthenticated attacker over the network via HTTP. Exploitation requires human interaction from a person other than the attacker (indicated by the UI:R vector), suggesting a Cross-Site Scripting (XSS) or similar UI-based injection attack. A successful exploit allows for unauthorized access to critical data and the ability to update, insert, or delete certain records. Notably, the vulnerability has a 'Scope: Changed' (S:C) impact, meaning a successful attack can impact components beyond the immediate telephony module.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial publication by Oracle