Executive brief
A vulnerability exists in the Oracle E-Business Suite's Advanced Outbound Telephony component, which is used by organizations to manage high-volume outbound calling operations. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to a significant breach of customer information or disruption of telephony operations.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit requires human interaction from a person other than the attacker (UI:R) and has a 'Changed' scope (S:C), meaning the impact can extend beyond the telephony component to other parts of the E-Business Suite. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of that data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: NVD published the vulnerability details.
- 2017-01-27: patched: Oracle released the January 2017 Critical Patch Update.