Executive brief
A critical vulnerability exists in Oracle iSupport, a customer service and support module within the Oracle E-Business Suite. A high-privileged attacker can exploit this flaw to take full control of the iSupport system, potentially leading to the theft of sensitive customer data or disruption of support operations. Because of the integrated nature of the suite, an attack on this component could also impact other connected business applications.
Technical details
This vulnerability affects the Internal Operations component of Oracle iSupport in Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an 'easily exploitable' flaw that allows a high-privileged attacker with network access via HTTP to compromise the system. The vulnerability is notable for a 'scope change' (S:C), meaning a successful exploit can impact components or products beyond the immediate security scope of Oracle iSupport. Successful exploitation results in a complete takeover of the affected component, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle iSupport 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory