Description
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker using HTTPS can create, delete, or modify critical data within Oracle Advanced Inbound Telephony and can also trigger a partial denial of service, affecting the integrity and availability of the system while confidentiality remains intact.

Affected Systems

Oracle Advanced Inbound Telephony, part of the Oracle E-Business Suite, is affected for all supported releases between version 12.2.3 and 12.2.15. Any system running one of these versions is vulnerable.

Risk and Exploitability

The CVSS 3.1 base score is 8.2, indicating a high risk. The vulnerability is exploitable over the network without authentication, and the EPSS score is not available, suggesting the attack surface is significant. The issue is not listed in the CISA KEV catalog but the straightforward exploitation path underscores the urgency of remediation.

Generated by OpenCVE AI on August 21, 2026 at 07:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a fixed version of Oracle Advanced Inbound Telephony.
  • Restrict HTTPS access to the component by allowing only trusted IP addresses or subnet ranges.
  • Enable logging for all access attempts, monitor for suspicious activity, and block offending IPs if necessary.

Generated by OpenCVE AI on August 21, 2026 at 07:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Allows Data Modification and Partial Denial of Service in Oracle Advanced Inbound Telephony

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Allows Data Modification and Partial Denial of Service in Oracle Advanced Inbound Telephony
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle advanced Inbound Telephony
CPEs cpe:2.3:a:oracle:advanced_inbound_telephony:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Inbound Telephony
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Advanced Inbound Telephony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:13.950Z

Reserved: 2026-08-04T22:06:34.592Z

Link: CVE-2026-70722

cve-icon Vulnrichment

Updated: 2026-08-19T12:11:47.674Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:24.670

Modified: 2026-08-24T15:51:35.700

Link: CVE-2026-70722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T07:15:11Z

Weaknesses