Access Vulnerability in Oracle Advanced Outbound Telephony Product of Oracle E-Business Suite
CVE-2020-2863
8.5HIGH
Summary
A vulnerability exists in Oracle Advanced Outbound Telephony, part of the Oracle E-Business Suite, that can be exploited by a low privileged attacker with network access via HTTP. This weakness allows the attacker to gain unauthorized access to sensitive data. While specifically targeted at Oracle Advanced Outbound Telephony, the implications of an exploit can extend to impacting additional products. Successful exploitation may permit an attacker to view, modify, insert, or delete critical data within Oracle Advanced Outbound Telephony, posing significant risks to data integrity and confidentiality.
Affected Version(s)
Advanced Outbound Telephony 12.1.1-12.1.3
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved