Description
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Inbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-08-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Advanced Inbound Telephony enables an attacker with low privileges and network access via HTTP to perform unauthorized read, update, insert, or delete operations on data that should be protected. The flaw can be exploited easily, potentially compromising confidentiality, integrity, and availability of data as well as causing a partial denial of service.

Affected Systems

The affected product is Oracle Advanced Inbound Telephony within Oracle E‑Business Suite, specifically the Internal Operations component. Versions 12.2.3 through 12.2.15 are impacted.

Risk and Exploitability

The CVSS v3.1 base score of 7.6 indicates high severity, yet the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network-based attack over HTTP where the attacker only requires low‑privilege credentials or none at all. Successful exploitation would provide unauthorized access to critical data and allow the attacker to partially disrupt service.

Generated by OpenCVE AI on August 21, 2026 at 06:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Oracle Advanced Inbound Telephony that addresses this vulnerability.
  • Restrict HTTP access to the application by configuring firewall rules or port‑level controls so that only trusted internal networks can reach it.
  • Enforce strict access control and authentication mechanisms to prevent low‑privileged users from performing update, insert or delete operations on sensitive data.

Generated by OpenCVE AI on August 21, 2026 at 06:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Oracle Advanced Inbound Telephony Remote Access Control Vulnerability

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Web Attack Allows Unauthorized Access and Partial Denial of Service in Oracle Advanced Inbound Telephony
Weaknesses CWE-284
CWE-863

Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Web Attack Allows Unauthorized Access and Partial Denial of Service in Oracle Advanced Inbound Telephony
Weaknesses CWE-284
CWE-863

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Inbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle advanced Inbound Telephony
CPEs cpe:2.3:a:oracle:advanced_inbound_telephony:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Inbound Telephony
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Advanced Inbound Telephony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:13.762Z

Reserved: 2026-08-04T22:06:34.592Z

Link: CVE-2026-70725

cve-icon Vulnrichment

Updated: 2026-08-19T12:11:42.665Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:25.023

Modified: 2026-08-24T15:51:28.813

Link: CVE-2026-70725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T07:00:12Z

Weaknesses