Executive brief
Oracle iSupport, a customer service portal within the Oracle E-Business Suite, contains a vulnerability that could allow an unauthorized person to view or modify certain data. To exploit this, an attacker would need to trick a legitimate user into performing a specific action, such as clicking a malicious link. If successful, this could lead to unauthorized changes to customer support records or the exposure of sensitive information.
Technical details
A vulnerability in the Internal Operations component of Oracle iSupport (Oracle E-Business Suite) allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is characterized by a CVSS 'Scope Change,' suggesting it may be a Cross-Site Scripting (XSS) or similar injection vulnerability that allows an attacker to impact other components beyond iSupport. Exploitation requires human interaction from a person other than the attacker (UI:R). Successful attacks can result in unauthorized read, update, insert, or delete access to a subset of data. Affected versions include 12.2.3 through 12.2.15.
Affected products
- Oracle iSupport 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published