Executive brief
A vulnerability exists in Oracle Quality, a component of the Oracle E-Business Suite used for enterprise quality management and data collection. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the Oracle Quality system. This could lead to the theft of sensitive business data, unauthorized modification of quality records, or a total disruption of quality management operations.
Technical details
This vulnerability is located in the Internal Operations component of Oracle Quality within Oracle E-Business Suite. It is classified under improper privilege management and authentication bypass (CWE-269, CWE-287, CWE-306). An attacker with low-privileged user access can exploit this flaw over the network via HTTP without any user interaction. A successful exploit allows for a complete takeover of the Oracle Quality product, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Quality 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory