Executive brief
A vulnerability exists in Oracle Price Protection, a component of the Oracle E-Business Suite used by organizations to manage price changes and supplier rebates. An attacker with basic user access to the corporate network could exploit this flaw to view, modify, or delete sensitive financial and operational data. This could lead to significant data integrity issues, unauthorized financial adjustments, or the exposure of proprietary pricing information.
Technical details
A vulnerability in the Internal Operations component of Oracle Price Protection (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to create, delete, or modify critical data, as well as gain complete read access to all data accessible by the Price Protection module. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle addressed this issue in the July 2026 Critical Patch Update.
Affected products
- Oracle Corporation Oracle Price Protection 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60714 was published to the NVD.