Executive brief
A vulnerability exists in the Oracle Application Object Library, a core component of the Oracle E-Business Suite used for managing application shared services. A low-privileged attacker could exploit this flaw to gain full control over the Application Object Library. This could lead to unauthorized access to sensitive business data, disruption of operations, and a total loss of system integrity.
Technical details
This vulnerability affects the Core component of the Oracle Application Object Library within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as difficult to exploit, requiring a low-privileged attacker to have network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle Application Object Library, impacting confidentiality, integrity, and availability. The attack complexity is high, suggesting specific conditions or timing may be required for a successful breach. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Application Object Library 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published