Executive brief
A vulnerability exists in the Oracle E-Business Suite component used for managing complex maintenance and repair operations. An attacker with basic user credentials can remotely access the system to view, modify, or delete sensitive maintenance data. This could lead to unauthorized changes in operational records or the exposure of proprietary maintenance information.
Technical details
This vulnerability affects the Common Utilities component of Oracle Complex Maintenance, Repair and Overhaul within Oracle E-Business Suite. It is classified as an improper access control or similar data validation issue that allows a low-privileged attacker with network access via HTTP to compromise the system. An exploit can lead to unauthorized 'update, insert, or delete' access to a subset of the application's data, as well as unauthorized read access. The attack does not require user interaction and has a low complexity. Affected versions range from 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Complex Maintenance, Repair and Overhaul (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory