Impact
A flaw in Oracle Advanced Outbound Telephony allows a low‑privileged attacker who can reach the system over HTTP to gain control of the product. The vulnerability is an improper access control flaw (CWE‑284). Based on the description, it is inferred that the attacker can execute arbitrary commands, bypassing the intended privilege boundaries and potentially affecting the entire telephony service. The impact covers confidentiality, integrity, and availability of the application, as the attacker can modify or erase data and disrupt operations.
Affected Systems
Oracle Advanced Outbound Telephony component Internal Operations versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 categorizes the flaw as high severity. The EPSS score of less than 1 % indicates that exploitation has been historically rare, and the version is not listed in the CISA KEV catalog. Attackers require only network access to an exposed HTTP endpoint and no user interaction. Based on the description, it is inferred that successful exploitation can lead to full takeover of the telephony service, compromising any data and potentially escalating privileges on the underlying host.
OpenCVE Enrichment