Description
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data as well as unauthorized read access to a subset of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the SDK client integration component of Oracle Advanced Inbound Telephony allows an attacker with low privileges and network access over HTTP to gain unauthorized read, insert, delete or update capability against accessible data, and to trigger a partial denial of service. This weakness is a CWE‑284 (Improper Access Control) flaw. The CVSS 3.1 base score of 6.3 reflects modest impacts on confidentiality, integrity and availability, with the vector indicating remote network access, low attack complexity, low privileges, no user interaction, and an unmodified system scope.

Affected Systems

Oracle Advanced Inbound Telephony, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The product is distributed by Oracle Corporation.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the impact of the vulnerability is significant enough that attackers able to reach the component over HTTP can modify critical data or disrupt service. The exploitation path requires only network connectivity to the component’s HTTP interface and does not require user interaction, making the attack vector straightforward for an adversary with network presence.

Generated by OpenCVE AI on August 4, 2026 at 17:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPUJul 2026 patch that addresses the SDK client integration flaw.
  • Limit HTTP exposure of the Oracle Advanced Inbound Telephony component by restricting access to trusted networks or by placing it behind a dedicated firewall.
  • Enforce the product’s default authentication and authorization for SDK endpoints, ensuring that only properly privileged users can perform read or write operations
  • If the SDK client integration is not required for business processes, disable the associated endpoints to reduce the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via SDK Client in Oracle Advanced Inbound Telephony

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via SDK Client in Oracle Advanced Inbound Telephony

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Exploit Compromise Oracle Advanced Inbound Telephony
Weaknesses CWE-276
CWE-285

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Exploit Compromise Oracle Advanced Inbound Telephony
Weaknesses CWE-276
CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: SDK client integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data as well as unauthorized read access to a subset of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle advanced Inbound Telephony
CPEs cpe:2.3:a:oracle:advanced_inbound_telephony:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Inbound Telephony
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Advanced Inbound Telephony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:21:00.532Z

Reserved: 2026-07-08T15:51:40.540Z

Link: CVE-2026-60491

cve-icon Vulnrichment

Updated: 2026-07-24T18:20:52.419Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses