Executive brief
A vulnerability exists in Oracle TeleSales, a component of the Oracle E-Business Suite used for managing sales activities and customer interactions. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain sales data. This could lead to unauthorized changes to business records or the exposure of sensitive sales information.
Technical details
A vulnerability in the Internal Operations component of Oracle TeleSales (Oracle E-Business Suite) allows for unauthorized data manipulation and disclosure. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to perform unauthorized updates, insertions, or deletions of certain data, as well as gain unauthorized read access to a subset of accessible information. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation TeleSales 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory