Executive brief
A vulnerability exists in the Oracle Assets module of the Oracle E-Business Suite, which is used by organizations to manage capital assets and financial depreciation. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive financial data. This could lead to significant data integrity issues or the unauthorized exposure of corporate asset records.
Technical details
A vulnerability in the Internal Operations component of Oracle Assets (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to create, delete, or modify critical data, as well as gain complete read access to all data within the Oracle Assets module. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle addressed this issue in the July 2026 Critical Patch Update.
Affected products
- Oracle Assets 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory