Executive brief
A vulnerability exists in Oracle Cash Management, a component of the Oracle E-Business Suite used by organizations to manage bank reconciliation and cash forecasting. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive financial data. This could result in the unauthorized viewing, modification, or deletion of critical business records, potentially impacting financial integrity and regulatory compliance.
Technical details
This vulnerability affects the Internal Operations component of Oracle Cash Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged user authentication and network connectivity via HTTP. Successful exploitation allows an attacker to bypass intended access controls to read, create, delete, or modify critical data within the Cash Management module. The vulnerability has a CVSS 3.1 base score of 8.1, primarily impacting confidentiality and integrity while availability remains unaffected. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Cash Management 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date