Executive brief
Oracle iSupplier Portal, a component of the Oracle E-Business Suite used for managing supplier communications and transactions, contains a security vulnerability in its Home Page component. A low-privileged attacker can exploit this flaw to take full control of the portal, potentially leading to the exposure of sensitive supplier data or disruption of procurement operations. For an attack to succeed, a legitimate user must perform a specific action, such as clicking a malicious link while logged in.
Technical details
A vulnerability in the Home Page component of Oracle iSupplier Portal (Oracle E-Business Suite) allows for a complete application takeover. While the specific vulnerability class is not explicitly named in the primary description, CISA-ADP has associated it with Cross-Site Request Forgery (CSRF), Open Redirect, and Weak Password Recovery mechanisms. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS, though it requires human interaction from a victim (User Interaction: Required). Successful exploitation grants the attacker full control over the iSupplier Portal, impacting confidentiality, integrity, and availability. Affected versions include 12.2.3 through 12.2.15.
Affected products
- Oracle iSupplier Portal 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date