Executive brief
Oracle Enterprise Asset Management, a tool used by organizations to manage physical assets and maintenance operations, contains a security vulnerability in its Internal Operations component. An attacker with basic user access to the system can exploit this flaw over the network to gain full control of the application. This could lead to the theft of sensitive operational data, unauthorized changes to maintenance records, or a complete shutdown of the asset management system.
Technical details
This vulnerability exists within the Internal Operations component of Oracle Enterprise Asset Management (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation can result in a complete takeover of the Oracle Enterprise Asset Management instance, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Enterprise Asset Management 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD