Impact
The vulnerability permits an unauthenticated attacker with network access through HTTP to gain control over Oracle Advanced Outbound Telephony. Successful exploitation lets the attacker create, delete, or modify critical data, effectively bypassing authentication and altering the system’s integrity and confidentiality. The weakness is an improper access control flaw that can lead to unauthorized data manipulation.
Affected Systems
Oracle Advanced Outbound Telephony in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, component Internal Operations, is affected. The product is used by organizations running the specified Oracle E‑Business Suite releases.
Risk and Exploitability
The CVSS 3.1 score of 9.1 indicates high severity for confidentiality and integrity. The EPSS score of less than 1% suggests that exploitation probability is currently low, and the vulnerability is not listed in CISA KEV. The likely attack path is a remote unauthenticated request over HTTP, which can be automated and does not require user interaction.
OpenCVE Enrichment