Impact
A vulnerability in Oracle Advanced Inbound Telephony enables an attacker with low privileges and network access via HTTP to perform unauthorized read, update, insert, or delete operations on data that should be protected. The flaw can be exploited easily, potentially compromising confidentiality, integrity, and availability of data as well as causing a partial denial of service.
Affected Systems
The affected product is Oracle Advanced Inbound Telephony within Oracle E‑Business Suite, specifically the Internal Operations component. Versions 12.2.3 through 12.2.15 are impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.6 indicates high severity, yet the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network-based attack over HTTP where the attacker only requires low‑privilege credentials or none at all. Successful exploitation would provide unauthorized access to critical data and allow the attacker to partially disrupt service.
OpenCVE Enrichment