Impact
The vulnerability is present in Oracle TeleSales, a component of Oracle E-Business Suite. It is classified under CWE-269, CWE-284, CWE-287, and CWE-306, representing weaknesses in privileged access management and privilege escalation. An attacker with only local or network read permissions who can reach the application through HTTP can exploit this to perform privileged operations, compromising the confidentiality, integrity, and availability of the system. The impact is a complete takeover of TeleSales, allowing the attacker to execute arbitrary commands or manipulate business data.
Affected Systems
Oracle TeleSales version 12.2.3 through 12.2.15 - part of the Internal Operations component - is affected. These releases are listed in the Oracle CPU Jul 2026 advisory and are the subject of the identified vulnerability.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a high‑severity flaw with full confidentiality, integrity, and availability impacts. The EPSS score is less than 1%, suggesting that the exploitation probability in the wild is low, though not zero. The vulnerability is not in CISA’s KEV catalog. The likely attack vector is HTTP traffic to the TeleSales service, inferred from the description that the flaw is exploitable via network access and requires little effort to craft malicious requests. Because the issue results in full system compromise and requires only baseline network access, the risk level remains significant for exposed environments.
OpenCVE Enrichment