Executive brief
A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the E-Business Suite used for managing high-volume customer communications. An attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify records, potentially impacting other integrated Oracle products. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to a significant breach of confidentiality and data integrity.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector via HTTP that requires human interaction (User Interaction: Required) from a person other than the attacker. The vulnerability is characterized by a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate software. Attackers can achieve unauthorized access to all accessible data (Confidentiality: High) and perform unauthorized updates or deletions of some data (Integrity: Low). The issue is addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published