Executive brief
A vulnerability exists in the Oracle Advanced Inbound Telephony component of the Oracle E-Business Suite, which manages incoming call routing and server communications. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive telephony data. Additionally, an exploit could cause a partial service outage, disrupting call center operations and data integrity.
Technical details
This vulnerability affects the Servers component of Oracle Advanced Inbound Telephony within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. A successful exploit allows an attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the application's data. Furthermore, the vulnerability can be leveraged to cause a partial denial of service (DoS), impacting the availability of telephony services. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Advanced Inbound Telephony 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD record published