Oracle Advanced Outbound Telephony Vulnerability in E-Business Suite
CVE-2020-2856

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability exists in Oracle Advanced Outbound Telephony within the Oracle E-Business Suite that allows an unauthenticated attacker with network access via HTTP to exploit the system. Although the vulnerability is specific to the Advanced Outbound Telephony component, successful exploitation can lead to unauthorized access to critical data, as well as privilege escalation that could enable attackers to manipulate or delete accessible data. This scenario requires human interaction from a user that is not the attacker, thereby creating risks beyond the primary product affected.

Affected Version(s)

Advanced Outbound Telephony 12.1.1-12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.