Impact
An unauthenticated attacker using HTTPS can create, delete, or modify critical data within Oracle Advanced Inbound Telephony and can also trigger a partial denial of service, affecting the integrity and availability of the system while confidentiality remains intact.
Affected Systems
Oracle Advanced Inbound Telephony, part of the Oracle E-Business Suite, is affected for all supported releases between version 12.2.3 and 12.2.15. Any system running one of these versions is vulnerable.
Risk and Exploitability
The CVSS 3.1 base score is 8.2, indicating a high risk. The vulnerability is exploitable over the network without authentication, and the EPSS score is not available, suggesting the attack surface is significant. The issue is not listed in the CISA KEV catalog but the straightforward exploitation path underscores the urgency of remediation.
OpenCVE Enrichment