Executive brief
A security vulnerability exists in Oracle Interaction Blending, a component of the Oracle E-Business Suite used for managing customer interactions. An attacker who already has basic access to the underlying server can exploit this flaw to gain full control over the application's data. This could lead to the unauthorized viewing, modification, or deletion of sensitive business information.
Technical details
This vulnerability affects the Internal Operations component of Oracle Interaction Blending within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an 'easily exploitable' flaw that requires the attacker to have local logon credentials to the infrastructure where the software is executing. Successful exploitation allows a low-privileged user to bypass intended access controls to achieve high confidentiality and integrity impacts, including the ability to create, delete, or modify all data accessible to the application. The attack does not require user interaction or high privileges, but is limited to the local environment (AV:L). Patching information is typically found in the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle Interaction Blending 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory