Executive brief
A vulnerability exists in Oracle's Advanced Outbound Telephony, a component of the E-Business Suite used for managing large-scale customer contact operations. An attacker with basic user access can exploit this flaw over the network to take full control of the telephony system. This could lead to the theft of sensitive customer data, disruption of call center operations, and unauthorized modification of business records.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the Internal Operations component of Oracle Advanced Outbound Telephony. It is easily exploitable by a low-privileged attacker with network access via HTTP. The exploit does not require user interaction and has a high impact on confidentiality, integrity, and availability, effectively allowing for a complete system takeover. Affected versions include Oracle E-Business Suite 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle Advanced Outbound Telephony 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory