Executive brief
A vulnerability exists in the Oracle Scheduler component of the Oracle E-Business Suite, which is used by organizations to automate business processes and manage job scheduling. An authorized user with low-level permissions could exploit this flaw to view, modify, or delete sensitive scheduling data. Additionally, an attacker could disrupt operations by causing a partial service outage, potentially impacting automated business workflows.
Technical details
This vulnerability affects the Rules UI component of Oracle Scheduler within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system without user interaction. Successful exploitation enables unauthorized read, update, insert, or delete access to a subset of Oracle Scheduler data. It also allows an attacker to trigger a partial denial of service (DoS) condition. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle E-Business Suite (Oracle Scheduler) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory