Executive brief
A critical vulnerability exists in Oracle Advanced Outbound Telephony, a component of the Oracle E-Business Suite used for managing high-volume outbound communications. An unauthorized person could remotely access the system over the internet to view, change, or delete sensitive business data. This could lead to a total loss of data confidentiality and integrity within the telephony module, potentially disrupting operations and exposing private customer or corporate information.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the Internal Operations component of Oracle Advanced Outbound Telephony. It is easily exploitable by an unauthenticated attacker with network access via HTTP. The flaw allows for the unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible by the product. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. While specific root cause details are not provided by the vendor, the high CVSS score reflects a significant impact on confidentiality and integrity without requiring user interaction.
Affected products
- Oracle Advanced Outbound Telephony 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD record published