Oracle Advanced Outbound Telephony Vulnerability in E-Business Suite
CVE-2020-14671
8.2HIGH
Summary
An improper authentication vulnerability exists in the Oracle Advanced Outbound Telephony component of the Oracle E-Business Suite. This flaw allows unauthenticated attackers with HTTP network access to exploit the system. Effective exploitation of this vulnerability requires user interaction, as attackers must coax a legitimate user into authenticating. While the vulnerability is specific to Oracle Advanced Outbound Telephony, its implications can extend to other components within the suite, potentially leading to unauthorized access to sensitive data and manipulation of stored information across the affected system.
Affected Version(s)
Advanced Outbound Telephony 12.1.1-12.1.3
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved