Executive brief
Oracle Enterprise Asset Management, a tool used by businesses to manage physical assets and maintenance operations, contains a security vulnerability in its Internal Operations component. A low-privileged user could potentially gain unauthorized access to view, modify, or delete certain business data. While the vulnerability is difficult to exploit, it could lead to unauthorized changes to maintenance records or asset information.
Technical details
A vulnerability exists in the Internal Operations component of Oracle Enterprise Asset Management (part of Oracle E-Business Suite). The flaw allows a low-privileged attacker with network access via HTTP to compromise the system, though Oracle notes the exploit complexity is high. Successful exploitation enables unauthorized read access to a subset of data and unauthorized update, insert, or delete access to some accessible data. The affected versions range from 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Enterprise Asset Management 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD