Executive brief
A vulnerability exists in the Party Search interface of Oracle Trading Community, a component of the Oracle E-Business Suite used for managing customer and partner data. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive business information. This could lead to significant data breaches or the corruption of critical organizational records.
Technical details
This vulnerability affects the Party Search UI component of Oracle Trading Community within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. The vulnerability allows an attacker to bypass intended access controls to achieve high confidentiality and integrity impacts, enabling full access to or modification of critical data. While the specific CWE is not provided in the advisory, the impact suggests an authorization or access control failure. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Trading Community (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed: Initial advisory publication
- 2026-07-21: advisory: NVD record created