Executive brief
A vulnerability exists in the Oracle Enterprise Command Center Framework, a component of the Oracle E-Business Suite used for data visualization and business intelligence. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft of critical information or the unauthorized modification and deletion of records within the system.
Technical details
A vulnerability in the Core component of Oracle Enterprise Command Center Framework (Oracle E-Business Suite) allows for unauthorized data access and manipulation. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read all accessible data within the framework or perform unauthorized updates, inserts, or deletions of certain data subsets. The vulnerability affects version V16 and has been assigned a CVSS 3.1 base score of 7.1, reflecting high confidentiality and low integrity impacts. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Enterprise Command Center Framework V16
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.