Executive brief
A vulnerability exists in the user interface of Oracle's Advanced Outbound Telephony, a component of the Oracle E-Business Suite used for managing high-volume outbound communications. An attacker could trick a user into performing an action that allows the attacker to view or modify sensitive business data. This could lead to unauthorized access to critical information or the alteration of records within the telephony system.
Technical details
This vulnerability affects the User Interface subcomponent of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation requires human interaction from a person other than the attacker (User Interaction: Required). The vulnerability has a 'Changed Scope' impact, meaning a successful attack can impact additional products beyond the telephony component itself. Attackers can achieve unauthorized access to all accessible data (Confidentiality: High) and perform unauthorized updates or deletions of some data (Integrity: Low).
Affected products
- Oracle Advanced Outbound Telephony 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Oracle Critical Patch Update (CPU) released