Executive brief
A vulnerability exists in the Oracle Financials Common Modules, a core component of the Oracle E-Business Suite used for managing corporate financial data. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive financial records. This could lead to significant data breaches, financial reporting inaccuracies, or unauthorized changes to business-critical information.
Technical details
A vulnerability in the Common Components of Oracle Financials Common Modules (Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker the ability to create, delete, or modify critical data, as well as gain complete read access to all data accessible by the module. The vulnerability affects versions 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Financials Common Modules (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory