Executive brief
A vulnerability exists in the Cover Letter component of Oracle Content Manager, a tool used within the Oracle E-Business Suite for managing digital assets and marketing content. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain business data. Additionally, an exploit could cause a partial service outage, disrupting normal business operations.
Technical details
This vulnerability affects the Cover Letter component of Oracle Content Manager within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged user authentication and network access via HTTP. A successful exploit allows an attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of data accessible to the Content Manager. Furthermore, the vulnerability can be leveraged to cause a partial denial of service (DoS). Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Corporation Content Manager (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory