Executive brief
A critical vulnerability exists in the Oracle Enterprise Command Center Framework, a component of the Oracle E-Business Suite used for data visualization and business intelligence. An attacker with basic user credentials can gain unauthorized access to view, modify, or delete sensitive business data across the system. This could lead to a total compromise of the application's data integrity and availability, potentially impacting other connected business systems.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the Core component of the Oracle Enterprise Command Center Framework. It is easily exploitable via HTTP by a low-privileged attacker with network access. The flaw involves a 'scope change' (Status: Changed in CVSS), meaning a successful exploit allows the attacker to impact components beyond the immediate framework. Impact includes unauthorized creation, deletion, or modification of all accessible data, as well as the ability to cause a partial denial of service. The vulnerability affects versions V15 and V16 of the framework.
Affected products
- Oracle Enterprise Command Center Framework V15, V16
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory