Executive brief
A critical vulnerability exists in the Oracle Application Object Library, a core component of the Oracle E-Business Suite used for managing business applications and data. An attacker with low-level user credentials can exploit this flaw over the network to gain full access to sensitive business information or modify critical data. Because this component is central to the suite, a successful attack could potentially compromise other integrated business systems and lead to significant operational disruption.
Technical details
This vulnerability affects the Core component of the Oracle Application Object Library in Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTPS. The exploit results in a scope change (S:C), meaning an attacker can potentially move beyond the Application Object Library to impact other products within the suite. Successful exploitation grants the attacker the ability to read, create, delete, or modify critical data. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle E-Business Suite (Application Object Library) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60773 was published to the NVD.