Executive brief
A vulnerability exists in the Workflow Notification Mailer component of Oracle E-Business Suite, which manages business process communications. An unauthenticated attacker could remotely access the system to view, modify, or delete sensitive workflow data. This could lead to unauthorized business process changes or a partial disruption of the workflow service.
Technical details
A vulnerability in the Workflow Notification Mailer component of Oracle Workflow (part of Oracle E-Business Suite) allows for unauthorized access via the HTTP protocol. The flaw is easily exploitable by an unauthenticated attacker with network access to the affected system. Successful exploitation enables the attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of Oracle Workflow data. Additionally, the vulnerability can be leveraged to cause a partial denial of service (DoS) affecting the availability of the workflow component. Affected versions include 12.2.3 through 12.2.15.
Affected products
- Oracle Corporation Oracle Workflow 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update