Description
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Advanced Outbound Telephony's Internal Operations component suffers an easily exploitable flaw that allows an attacker with low privileges and network access via HTTP to compromise the entire application. Successful exploitation results in full takeover, allowing attackers to read confidential data, modify or delete information, and disrupt services. The weakness is a critical security flaw that directly impacts confidentiality, integrity, and availability of the system.

Affected Systems

The flaw affects Oracle Corporation's Advanced Outbound Telephony within Oracle E‑Business Suite in versions 12.2.3 through 12.2.15. Deployments of these versions are vulnerable, as the flaw resides in the core Internal Operations component.

Risk and Exploitability

The CVSS v3.1 Base Score of 8.8 indicates a high‑severity risk, and the vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) shows that an attacker can exploit the vulnerability remotely over HTTP with limited privileges and no user interaction. The EPSS score of < 1% suggests that widespread exploitation is currently unlikely, but the high impact and clear exploitation path warrant immediate attention. The vulnerability is not listed in CISA’s KEV catalog, but the potential for full compromise makes it a top priority for remediation.

Generated by OpenCVE AI on June 17, 2026 at 19:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch released by Oracle that fixes the vulnerability in Oracle Advanced Outbound Telephony for all affected versions 12.2.3‑12.2.15
  • Restrict HTTP access to the Oracle Advanced Outbound Telephony component to trusted IP ranges or tunnel traffic through a VPN, thereby limiting exposure to low‑privileged attackers on the network
  • Enforce strict role‑based access control and privilege checks for all critical functions in the application, and monitor logs for any unauthorized or anomalous activity

Generated by OpenCVE AI on June 17, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle advanced Outbound Telephony
CPEs cpe:2.3:a:oracle:advanced_outbound_telephony:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Outbound Telephony
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Advanced Outbound Telephony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T19:37:09.068Z

Reserved: 2026-05-18T15:55:10.313Z

Link: CVE-2026-46950

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T04:00:02Z

Weaknesses

No weakness.