Executive brief
A vulnerability exists in Oracle TeleSales, a component of the Oracle E-Business Suite used by sales teams to manage customer interactions and leads. A low-privileged user can exploit this flaw over the network to gain full control of the TeleSales application. This could lead to the unauthorized access, modification, or deletion of sensitive sales data and customer information, potentially disrupting business operations.
Technical details
A vulnerability in the Internal Operations component of Oracle TeleSales (Oracle E-Business Suite) allows for a complete application compromise. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker full control over the TeleSales environment, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation TeleSales 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD