Executive brief
A vulnerability exists in Oracle TeleSales, a component of the Oracle E-Business Suite used for managing sales activities and customer interactions. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft, modification, or deletion of critical sales and customer information, potentially disrupting business operations and compromising data integrity.
Technical details
A vulnerability in the Internal Operations component of Oracle TeleSales (versions 12.2.3 through 12.2.15) allows for unauthorized data access and modification. The flaw is categorized as easily exploitable and requires only low-privileged user authentication. An attacker can exploit this over the network via HTTP to achieve high confidentiality and integrity impacts, effectively gaining full access to all data accessible by the TeleSales module. While the specific CWE is not provided in the advisory, the impact suggests a failure in authorization or access control within the Internal Operations component. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle TeleSales 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory