Impact
A vulnerability in the SDK client integration component of Oracle Advanced Inbound Telephony allows an attacker with low privileges and network access over HTTP to gain unauthorized read, insert, delete or update capability against accessible data, and to trigger a partial denial of service. This weakness is a CWE‑284 (Improper Access Control) flaw. The CVSS 3.1 base score of 6.3 reflects modest impacts on confidentiality, integrity and availability, with the vector indicating remote network access, low attack complexity, low privileges, no user interaction, and an unmodified system scope.
Affected Systems
Oracle Advanced Inbound Telephony, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The product is distributed by Oracle Corporation.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the impact of the vulnerability is significant enough that attackers able to reach the component over HTTP can modify critical data or disrupt service. The exploitation path requires only network connectivity to the component’s HTTP interface and does not require user interaction, making the attack vector straightforward for an adversary with network presence.
OpenCVE Enrichment