← Vulnerability feed

Vulnerability record · CVE-2020-2871 · published 15 April 2020

CVE-2020-2871: Oracle Advanced Outbound Telephony UI flaw allows unauthenticated data access

Oracle · Advanced Outbound Telephony

Oracle Advanced Outbound Telephony (part of Oracle E-Business Suite) has a vulnerability in its User Interface component affecting versions 12.1.1-12.1.3 and 12.2.3-12.2.9. An unauthenticated network attacker can exploit it, but a person other than the attacker must interact with the application. The record gives no root-cause detail beyond the UI component, so the exact flaw mechanism is unknown.

8.2 CVSS 3.1 High EPSS 66% · top 0.7%
8.2CVSS 3.1 base score, v2 5.8
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.2 with no authentication required and high confidentiality impact, plus a very high EPSS percentile, though exploitation requires user interaction and no KEV listing exists.

What it is

Oracle Advanced Outbound Telephony (part of Oracle E-Business Suite) has a vulnerability in its User Interface component affecting versions 12.1.1-12.1.3 and 12.2.3-12.2.9. An unauthenticated network attacker can exploit it, but a person other than the attacker must interact with the application. The record gives no root-cause detail beyond the UI component, so the exact flaw mechanism is unknown.

Impact

Successful exploitation can give unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony data, plus unauthorized insert, update or delete of some of that data. The scope change means other products may also be significantly impacted.

Attack surface

Reached over the network via HTTP against the Oracle Advanced Outbound Telephony user interface; no authentication is required, but the attack requires human interaction by another user. The CVSS vector confirms AV:N, PR:N, UI:R and scope change.

Exploitation

Not listed in CISA KEV and no public exploit references are provided; only vendor advisories are cited. EPSS is high at 0.66186 (99.2nd percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.

What to do

  • Apply the Oracle April 2020 Critical Patch Update (cpuapr2020) for Advanced Outbound Telephony on affected 12.1.1-12.1.3 and 12.2.3-12.2.9 versions.
  • Restrict network access to the E-Business Suite HTTP interface to trusted users and networks; do not expose it directly to the internet.
  • Enforce user awareness and phishing-resistant controls, since exploitation requires a victim to interact with attacker-supplied content.
  • Monitor and limit privileges on Advanced Outbound Telephony data to reduce the impact of unauthorized read or write access.
  • If patching is delayed, consider temporarily disabling or restricting the affected UI component where operationally feasible.

Detection

  • Review E-Business Suite HTTP access logs for anomalous or unexpected requests to Advanced Outbound Telephony UI endpoints from unauthenticated or unusual sources.
  • Alert on unexpected database read or write activity against Advanced Outbound Telephony tables outside normal business patterns.
  • Correlate user-reported suspicious links or pages with subsequent E-Business Suite session activity to catch interaction-based exploitation.
  • Track Oracle CPU application status for E-Business Suite hosts and flag systems still running affected versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-2871 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-46949Oracle advanced outbound telephony improper access control vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …EPSS 0.43%8.8CVE-2026-60829Oracle advanced outbound telephony improper access control vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …EPSS 0.43%8.8CVE-2026-46947Oracle advanced outbound telephony improper access control vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …EPSS 0.43%8.8CVE-2026-46950Oracle advanced outbound telephony improper access control vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that …EPSS 0.43%8.5CVE-2020-2863Oracle advanced outbound telephony vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are a…EPSS 1.1%8.2CVE-2020-14670Oracle advanced outbound telephony vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Settings). Supported versions that are affecte…EPSS 1.3%8.2CVE-2020-14671Oracle advanced outbound telephony vulnerabilityVulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are a…EPSS 1.3%8.2CVE-2020-2852Oracle Advanced Outbound Telephony Calendar flaw allows unauthenticated data accessA vulnerability in the Calendar component of Oracle Advanced Outbound Telephony (Oracle E-Business Suite) affects versions 12.1.1 through 12.1.3. An …EPSS 66%analysed

Source: NIST National Vulnerability Database (record CVE-2020-2871), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.