Executive brief
A vulnerability exists in the Partner Dashboard component of Oracle Partner Management, a tool used by businesses to manage relationships and data with external partners. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain partner data. Additionally, an exploit could cause a partial service outage, disrupting normal business operations and partner interactions.
Technical details
This vulnerability affects the Partner Dashboard component of Oracle Partner Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTPS. Successful exploitation allows an attacker to perform unauthorized read, update, insert, or delete operations on a subset of accessible data. It also enables a partial denial of service (DoS) attack. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Oracle Partner Management (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published