Vulnerability record · CVE-2020-2871 · published 15 April 2020
CVE-2020-2871: Oracle Advanced Outbound Telephony UI flaw allows unauthenticated data access
Oracle · Advanced Outbound Telephony
Oracle Advanced Outbound Telephony (part of Oracle E-Business Suite) has a vulnerability in its User Interface component affecting versions 12.1.1-12.1.3 and 12.2.3-12.2.9. An unauthenticated network attacker can exploit it, but a person other than the attacker must interact with the application. The record gives no root-cause detail beyond the UI component, so the exact flaw mechanism is unknown.
Description
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Automated analysis
high priorityCVSS 8.2 with no authentication required and high confidentiality impact, plus a very high EPSS percentile, though exploitation requires user interaction and no KEV listing exists.
What it is
Oracle Advanced Outbound Telephony (part of Oracle E-Business Suite) has a vulnerability in its User Interface component affecting versions 12.1.1-12.1.3 and 12.2.3-12.2.9. An unauthenticated network attacker can exploit it, but a person other than the attacker must interact with the application. The record gives no root-cause detail beyond the UI component, so the exact flaw mechanism is unknown.
Impact
Successful exploitation can give unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony data, plus unauthorized insert, update or delete of some of that data. The scope change means other products may also be significantly impacted.
Attack surface
Reached over the network via HTTP against the Oracle Advanced Outbound Telephony user interface; no authentication is required, but the attack requires human interaction by another user. The CVSS vector confirms AV:N, PR:N, UI:R and scope change.
Exploitation
Not listed in CISA KEV and no public exploit references are provided; only vendor advisories are cited. EPSS is high at 0.66186 (99.2nd percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.
What to do
- Apply the Oracle April 2020 Critical Patch Update (cpuapr2020) for Advanced Outbound Telephony on affected 12.1.1-12.1.3 and 12.2.3-12.2.9 versions.
- Restrict network access to the E-Business Suite HTTP interface to trusted users and networks; do not expose it directly to the internet.
- Enforce user awareness and phishing-resistant controls, since exploitation requires a victim to interact with attacker-supplied content.
- Monitor and limit privileges on Advanced Outbound Telephony data to reduce the impact of unauthorized read or write access.
- If patching is delayed, consider temporarily disabling or restricting the affected UI component where operationally feasible.
Detection
- Review E-Business Suite HTTP access logs for anomalous or unexpected requests to Advanced Outbound Telephony UI endpoints from unauthenticated or unusual sources.
- Alert on unexpected database read or write activity against Advanced Outbound Telephony tables outside normal business patterns.
- Correlate user-reported suspicious links or pages with subsequent E-Business Suite session activity to catch interaction-based exploitation.
- Track Oracle CPU application status for E-Business Suite hosts and flag systems still running affected versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpuapr2020.html | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpuapr2020.html | Vendor Advisory |
Track CVE-2020-2871 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-2871), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.