Unspecified Vulnerability in Oracle E-Business Suite by Oracle
CVE-2016-3532
8.2HIGH
What is CVE-2016-3532?
An unspecified vulnerability in the Oracle Advanced Inbound Telephony component of Oracle E-Business Suite (versions 12.1.1, 12.1.2, and 12.1.3) may allow remote attackers to compromise data confidentiality and integrity. This vulnerability is associated with issues related to SDK client integration. Although Oracle has not confirmed claims regarding multiple cross-site scripting (XSS) vulnerabilities, it is important to be aware that these could enable attackers to inject arbitrary web scripts or HTML through undefined mechanisms.