Description
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Outbound Telephony accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-06-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits an unauthenticated attacker with network access through HTTP to gain control over Oracle Advanced Outbound Telephony. Successful exploitation lets the attacker create, delete, or modify critical data, effectively bypassing authentication and altering the system’s integrity and confidentiality. The weakness is an improper access control flaw that can lead to unauthorized data manipulation.

Affected Systems

Oracle Advanced Outbound Telephony in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, component Internal Operations, is affected. The product is used by organizations running the specified Oracle E‑Business Suite releases.

Risk and Exploitability

The CVSS 3.1 score of 9.1 indicates high severity for confidentiality and integrity. The EPSS score of less than 1% suggests that exploitation probability is currently low, and the vulnerability is not listed in CISA KEV. The likely attack path is a remote unauthenticated request over HTTP, which can be automated and does not require user interaction.

Generated by OpenCVE AI on June 17, 2026 at 19:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch that corrects the improper access control flaw, addressing CWE‑284 and CWE‑285.
  • Restrict HTTP access to Oracle Advanced Outbound Telephony to trusted internal IPs and networks to reduce exploitation opportunities for the access control weakness (CWE‑284).
  • Enforce HTTPS and disable legacy HTTP interfaces to further limit the attack surface related to the authentication bypass flaw (CWE‑284).
  • Enable comprehensive logging for authentication and data modification events, and regularly audit logs to detect unauthorized activity arising from the improper access control vulnerability (CWE‑284).

Generated by OpenCVE AI on June 17, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Outbound Telephony accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle advanced Outbound Telephony
CPEs cpe:2.3:a:oracle:advanced_outbound_telephony:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Outbound Telephony
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Advanced Outbound Telephony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T19:34:37.646Z

Reserved: 2026-05-18T15:55:10.313Z

Link: CVE-2026-46949

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T00:00:10Z

Weaknesses

No weakness.