Impact
The vulnerability is an access‑control flaw (CWE‑284) in the Oracle Advanced Inbound Telephony component of Oracle E‑Business Suite. The flaw allows an attacker who has a low‑privileged account with network reach to the HTTP interface to perform unauthorized updates, inserts, or deletes, read portions of protected data, and trigger a partial denial of service. These capabilities lead to breaches of confidentiality, integrity, and availability for the affected Telephony data.
Affected Systems
Affected systems are Oracle Advanced Inbound Telephony deployments running Oracle E‑Business Suite versions 12.2.3, 12.2.4, up to and including 12.2.15. Other versions outside this range are not listed as vulnerable. The issue resides in the server component accessed via HTTP.
Risk and Exploitability
The CVSS v3.1 base score of 6.3 signals moderate severity, while an EPSS score of less than 1 % indicates a very low likelihood of real‑world exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the flaw over the network through the public or internal HTTP endpoint and only need a low‑privilege account, so the attack vector is remote. Although exploitation probability is low, the potential for unauthorized data manipulation warrants immediate remediation.
OpenCVE Enrichment