Executive brief
A vulnerability exists in the Oracle Trading Community component of the Oracle E-Business Suite, which is used by organizations to manage master data for customers and partners. A high-privileged user can exploit this flaw over the network to gain full control over the Trading Community module. This could lead to the unauthorized modification or theft of sensitive business partner data and disruption of related business operations.
Technical details
This vulnerability affects the Party Search UI component of Oracle Trading Community within Oracle E-Business Suite versions 12.2.3 through 12.2.12. It is classified as an easily exploitable flaw that requires high privileges (PR:H) and network connectivity via HTTP. Successful exploitation allows an attacker to fully compromise the component, impacting confidentiality, integrity, and availability (C:H/I:H/A:H). While the specific CWE is not detailed in the advisory, the impact is described as a complete takeover of the affected product. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Trading Community (E-Business Suite) 12.2.3-12.2.12
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date