Executive brief
A vulnerability exists in the Oracle Enterprise Command Center Framework, a component of the Oracle E-Business Suite used for data visualization and business intelligence. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to a significant breach of confidential information or the corruption of critical business records.
Technical details
An improper access control vulnerability (CWE-284) exists in the Core component of Oracle Enterprise Command Center Framework versions V15 and V16. The flaw is easily exploitable over the network via HTTPS by an unauthenticated attacker. Successful exploitation requires human interaction from a legitimate user (UI:R), suggesting a vector such as Cross-Site Request Forgery (CSRF) or a similar client-side attack. If successful, the attacker can achieve high confidentiality and integrity impacts, gaining the ability to create, delete, or modify all data accessible within the framework. Availability is not impacted (A:N).
Affected products
- Oracle Enterprise Command Center Framework V15, V16
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle published security alert cspujun2026.html