Executive brief
A vulnerability exists in Oracle Advanced Outbound Telephony, a component of the Oracle E-Business Suite used for managing large-scale automated phone communications. A low-privileged user can exploit this flaw over the network to gain full control of the system. This could lead to the theft of sensitive customer data, disruption of communication services, and unauthorized access to broader business operations.
Technical details
This vulnerability (CWE-284) affects the Internal Operations component of Oracle Advanced Outbound Telephony within Oracle E-Business Suite. It is classified as an improper access control issue that is easily exploitable via HTTP. An attacker with low-level credentials can leverage this flaw to achieve a complete takeover of the affected product, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle has addressed this in their June 2026 security update.
Affected products
- Oracle Advanced Outbound Telephony 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle security alert published