Executive brief
A vulnerability exists in the Internal Operations component of Oracle Sales Offline, a tool within the Oracle E-Business Suite used by sales teams to manage data while disconnected from the main network. An attacker with basic user credentials could exploit this flaw over the network to gain full access to sensitive sales data. This could result in the unauthorized viewing, modification, or deletion of critical business information, potentially disrupting sales operations and compromising proprietary data.
Technical details
This vulnerability affects the Internal Operations component of Oracle Sales Offline in Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires only low-privileged user credentials and network connectivity via HTTP. The attack does not require user interaction. Successful exploitation grants the attacker high confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of critical data, as well as complete read access to all data accessible by the Sales Offline component. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Oracle Sales Offline (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60735 was published to the NVD.