Executive brief
A critical vulnerability exists in the Oracle Universal Work Queue component of the Oracle E-Business Suite. This software is used by organizations to manage and distribute tasks across various business applications. An attacker with low-level access could exploit this flaw to take full control of the system, potentially leading to the theft of sensitive business data or a complete disruption of operations.
Technical details
A vulnerability in the Work Provider Site Level Administration component of Oracle Universal Work Queue (Oracle E-Business Suite) allows a low-privileged attacker with network access via HTTP to compromise the system. The flaw is characterized by a CVSS 3.1 score of 9.9, indicating a high impact on confidentiality, integrity, and availability. Notably, the exploit involves a 'scope change' (S:C), meaning a successful attack can impact other components or products beyond the Universal Work Queue itself. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle E-Business Suite Universal Work Queue 12.2.3-12.2.15
Timeline
- 2026-05-28: disclosed: Initial disclosure by Oracle
- 2026-05-28: advisory: NVD publication date