Executive brief
Oracle Advanced Inbound Telephony is a telephony component within Oracle E-Business Suite used for managing inbound phone communications. An unauthenticated attacker with network access can bypass security controls and modify or delete critical customer and operational data, or temporarily disrupt service availability.
Technical details
This vulnerability is an easily exploitable authentication bypass in Oracle Advanced Inbound Telephony (versions 12.2.3 to 12.2.15) affecting the Internal Operations component. The flaw allows an unauthenticated attacker to access the application via HTTPS (network vector) without authentication, granting unauthorized ability to create, modify, or delete data and cause partial denial of service. No preconditions such as user interaction or prior authentication are required. The vulnerability impacts both data integrity and service availability. Patch availability is expected from Oracle's regular Critical Patch Updates.
Affected products
- Oracle E-Business Suite Advanced Inbound Telephony 12.2.3 through 12.2.15
Timeline
- 2026-08-18: disclosed