← Vulnerability feed

Vulnerability record · CVE-2020-2852 · published 15 April 2020

CVE-2020-2852: Oracle Advanced Outbound Telephony Calendar flaw allows unauthenticated data access

Oracle · Advanced Outbound Telephony

A vulnerability in the Calendar component of Oracle Advanced Outbound Telephony (Oracle E-Business Suite) affects versions 12.1.1 through 12.1.3. An unauthenticated network attacker can exploit it, but a successful attack requires human interaction from another person. It can lead to unauthorized access to critical data and modification of some accessible data.

8.2 CVSS 3.1 High EPSS 66% · top 0.7%
8.2CVSS 3.1 base score, v2 5.8
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Calendar). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS score is 8.2 (High) with network reachability and no authentication required, though user interaction is needed; EPSS is very high, but no known active exploitation is confirmed.

What it is

A vulnerability in the Calendar component of Oracle Advanced Outbound Telephony (Oracle E-Business Suite) affects versions 12.1.1 through 12.1.3. An unauthenticated network attacker can exploit it, but a successful attack requires human interaction from another person. It can lead to unauthorized access to critical data and modification of some accessible data.

Impact

An attacker can gain unauthorized read access to critical data and limited insert, update, or delete access within Oracle Advanced Outbound Telephony. The scope change means other products may also be significantly impacted.

Attack surface

Reachable over the network via HTTP without authentication, but exploitation requires a user to perform some action (UI:R). The CVSS vector confirms AV:N/AC:L/PR:N/UI:R/S:C.

Exploitation

Not listed in CISA KEV. EPSS probability is 0.66186 (99.2nd percentile), indicating a high likelihood of exploitation activity, but no public exploit references are provided beyond the vendor advisory.

What to do

  • Apply the Oracle Critical Patch Update for April 2020 (cpuapr2020) to affected Oracle E-Business Suite versions 12.1.1-12.1.3.
  • If patching is delayed, restrict network access to the Oracle Advanced Outbound Telephony Calendar component to trusted users and networks.
  • Monitor for and block suspicious HTTP requests targeting the Calendar component, especially those that could trigger user interaction.
  • Educate users not to click untrusted links or open unexpected content that could initiate the required human interaction.
  • Verify that additional products in scope are reviewed for impact and patched as needed.

Detection

  • Monitor web server and application logs for unusual HTTP requests to Oracle Advanced Outbound Telephony Calendar endpoints, particularly from unauthenticated sources.
  • Look for anomalous database queries or data access patterns involving the Advanced Outbound Telephony schema that could indicate unauthorized read or write activity.
  • Track user reports of unexpected pop-ups, redirects, or content that may be part of a social engineering attempt to trigger the required interaction.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-2852 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-46949Oracle advanced outbound telephony improper access control vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …EPSS 0.43%8.8CVE-2026-60829Oracle advanced outbound telephony improper access control vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …EPSS 0.43%8.8CVE-2026-46947Oracle advanced outbound telephony improper access control vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …EPSS 0.43%8.8CVE-2026-46950Oracle advanced outbound telephony improper access control vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …EPSS 0.43%8.5CVE-2020-2863Oracle advanced outbound telephony vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are a…EPSS 1.1%8.2CVE-2020-14670Oracle advanced outbound telephony vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Settings). Supported versions that are affecte…EPSS 1.3%8.2CVE-2020-14671Oracle advanced outbound telephony vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are a…EPSS 1.3%8.2CVE-2020-2871Oracle Advanced Outbound Telephony UI flaw allows unauthenticated data accessOracle Advanced Outbound Telephony (part of Oracle E-Business Suite) has a vulnerability in its User Interface component affecting versions 12.1.1-12…EPSS 66%analysed

Source: NIST National Vulnerability Database (record CVE-2020-2852), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.