Executive brief
A vulnerability exists in the Oracle Common Application Components of the Oracle E-Business Suite, which provides shared functionality for various business applications. A low-privileged attacker could exploit this flaw to gain unauthorized access to sensitive data or modify critical business information. This could lead to significant data breaches, unauthorized changes to financial or operational records, and partial service disruptions across multiple Oracle products.
Technical details
This vulnerability affects Oracle Common Application Components (Oracle Common Modules) versions 12.2.3 through 12.2.15 within the Oracle E-Business Suite. It is characterized by a high attack complexity, requiring a low-privileged attacker to have network access via HTTP. The exploit results in a scope change (S:C), meaning the impact can extend beyond the immediate component to other parts of the E-Business Suite. Successful exploitation allows for unauthorized creation, deletion, or modification of critical data, as well as full read access to all accessible data and a partial denial of service. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle Common Application Components (Oracle Common Modules) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published