Executive brief
Oracle Advanced Inbound Telephony is a component of Oracle E-Business Suite that handles incoming phone call routing and management for enterprise contact centers. A network-accessible vulnerability allows a low-privilege user to access sensitive customer data, modify records, and disrupt service, affecting confidentiality, data integrity, and system availability.
Technical details
This vulnerability in Oracle Advanced Inbound Telephony's Internal Operations component allows a low-privileged attacker with network access via HTTP to bypass security controls. The flaw enables unauthorized read access to critical data, unauthorized modification (update/insert/delete) of some accessible data, and the ability to trigger partial denial of service. Exploitation requires valid low-privilege credentials and network connectivity to the affected HTTP interface, but no additional user interaction. Affected versions are 12.2.3 through 12.2.15. Patch availability and specific remediation steps should be obtained from Oracle's official security advisories.
Affected products
- Oracle Advanced Inbound Telephony 12.2.3–12.2.15
Timeline
- 2026-08-18: disclosed