Executive brief
A vulnerability exists in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite, which is used to manage high-volume outbound calling operations. An attacker could exploit this flaw to gain unauthorized access to sensitive data or modify records, potentially disrupting business operations and compromising customer information. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The attack requires human interaction from a person other than the attacker (User Interaction: Required) and has a 'Changed' scope, meaning the impact can extend beyond the immediate component to other parts of the E-Business Suite. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: NVD publication date
- 2017-01-17: patched: Oracle January 2017 Critical Patch Update released