Impact
A remote attacker with low privileges can send HTTP requests to the internal operations component of Oracle TeleSales and create, modify, or delete critical data. The vulnerability stems from missing or incorrect authorization checks, allowing the attacker to bypass normal protections. The resulting impact compromises both confidentiality and integrity of the data accessible through Oracle TeleSales, without affecting availability.
Affected Systems
Oracle TeleSales is part of Oracle E‑Business Suite. All supported releases from 12.2.3 to 12.2.15 are impacted. These versions have been identified as vulnerable by Oracle’s security advisory for July 2026.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 reflects high severity, yet the EPSS score of less than 1 % suggests that exploitation is presently rare and no public exploit has been observed. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the weakness remotely over HTTP; the low privileges required imply that internal or compromised network accounts are sufficient for successful attacks.
OpenCVE Enrichment