Executive brief
A vulnerability exists in the Oracle Advanced Inbound Telephony component of the Oracle E-Business Suite, which manages incoming call center communications. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive telephony data. Additionally, this could lead to a partial service outage, disrupting call center operations and data integrity.
Technical details
This vulnerability affects the SDK client integration component of Oracle Advanced Inbound Telephony (versions 12.2.3 through 12.2.15). It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. A successful exploit allows an attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the application's data. Furthermore, the vulnerability can be leveraged to cause a partial denial of service (DoS), impacting the availability of the telephony integration. The issue is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Advanced Inbound Telephony (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.