Executive brief
A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the E-Business Suite used for managing high-volume customer communications. An attacker could exploit this to gain unauthorized access to sensitive business data or modify records. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could then allow the attacker to compromise the system and potentially impact other connected business applications.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within the Oracle E-Business Suite. It is an unauthenticated, network-based attack vector (HTTP) that requires user interaction (UI:R), suggesting a Cross-Site Scripting (XSS) or similar UI-redirection flaw. The vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate telephony module. Attackers can achieve high confidentiality impact and partial integrity impact, allowing for the unauthorized viewing of all accessible data and the modification of some records. Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial publication by Oracle