Executive brief
A vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite, which manages automated outbound calling operations. An attacker with basic user access can exploit this flaw over the network to take full control of the telephony system. This could lead to the unauthorized access of sensitive customer data, disruption of communication services, and total loss of system integrity.
Technical details
This vulnerability affects the Internal Operations component of Oracle Advanced Outbound Telephony within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation can result in a complete takeover of the affected component, impacting confidentiality, integrity, and availability (CVSS 8.8). While the specific CWE is not detailed in the advisory, the impact suggests a significant authorization or injection-based bypass. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Advanced Outbound Telephony 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.