Executive brief
A vulnerability exists in Oracle Enterprise Asset Management, a tool used by organizations to manage physical assets and maintenance operations. An attacker with basic user credentials can exploit this flaw over the network to access sensitive business data or disrupt the system's availability. This could lead to the exposure of critical maintenance records or a partial shutdown of the asset management service.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the Internal Operations component of Oracle Enterprise Asset Management. It is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation does not require user interaction and can result in unauthorized high-impact confidentiality loss, allowing access to all data within the component. Additionally, the attacker can cause a partial denial of service (DoS), impacting system availability. The vulnerability is addressed in the Oracle Critical Patch Update for June 2026.
Affected products
- Oracle Enterprise Asset Management 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory