Executive brief
Oracle Quality, a component of the Oracle E-Business Suite used for managing enterprise quality control and compliance, contains a security vulnerability in its Internal Operations component. A user with low-level access to the system can exploit this flaw over the network to gain full control of the application. This could lead to the unauthorized modification of quality standards, theft of sensitive operational data, or a complete shutdown of quality management processes.
Technical details
This vulnerability exists in the Internal Operations component of Oracle Quality within the Oracle E-Business Suite. It is classified under improper privilege management and authentication bypass (CWE-269, CWE-287, CWE-306). An attacker with low-privileged credentials can exploit this flaw over HTTP without any user interaction. A successful exploit results in a complete takeover of the Oracle Quality product, impacting the confidentiality, integrity, and availability of the system. Affected versions range from 12.2.3 through 12.2.15.
Affected products
- Oracle Quality 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory