Executive brief
Oracle E-Business Intelligence, a component of the Oracle E-Business Suite used for corporate data analysis and reporting, contains a security vulnerability. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft, deletion, or modification of critical organizational information, potentially disrupting operations and compromising data integrity.
Technical details
A vulnerability exists in the Definition component of Oracle E-Business Intelligence (part of Oracle E-Business Suite). The flaw is classified as easily exploitable and requires only low-privileged authentication. An attacker can exploit this over the network via HTTP to achieve unauthorized creation, deletion, or modification of data. The impact is limited to Confidentiality and Integrity, with no reported impact on Availability (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Affected versions include 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle E-Business Intelligence 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD