Executive brief
A vulnerability exists in the Oracle Applications Manager, a tool used by administrators to manage and monitor Oracle E-Business Suite environments. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of certain administrative information, potentially impacting business operations and data integrity.
Technical details
This vulnerability affects the Oracle Diagnostics Interfaces component within Oracle Applications Manager (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation enables the attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the data accessible to the Applications Manager. The vulnerability has a CVSS 3.1 base score of 6.5, reflecting impacts to both confidentiality and integrity, though it does not appear to impact service availability.
Affected products
- Oracle Applications Manager (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published as part of Oracle Critical Patch Update (CPU) July 2026