Executive brief
A critical vulnerability exists in Oracle iSupport, a customer service and support module within the Oracle E-Business Suite. A high-privileged attacker can exploit this flaw over the network to gain full control of the iSupport system. Because of the integrated nature of the suite, a successful attack could also allow the intruder to compromise other connected business applications and data.
Technical details
This vulnerability affects the Internal Operations component of Oracle iSupport within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires high administrative privileges (PR:H) but no user interaction. The attack vector is network-based via HTTP. A successful exploit results in a 'scope change' (S:C), meaning the attacker can move beyond the iSupport component to impact other parts of the E-Business Suite environment, leading to a total loss of confidentiality, integrity, and availability. Oracle has addressed this in their June 2026 security update.
Affected products
- Oracle iSupport (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory