Executive brief
A security vulnerability exists in Oracle Sales Offline, a component of the Oracle E-Business Suite used by sales teams to manage data without a constant internet connection. A high-privileged attacker could exploit this flaw to take full control of the application, potentially leading to the theft of sensitive sales data or disruption of business operations. Because this component integrates with other parts of the E-Business Suite, an attack could also impact additional connected business systems.
Technical details
This vulnerability affects the Internal Operations component of Oracle Sales Offline within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is characterized by a CVSS 3.1 score of 8.0, indicating a high impact on confidentiality, integrity, and availability. The attack vector is network-based via HTTP, though exploitation is considered difficult (High Attack Complexity) and requires high-privileged credentials. A successful exploit results in a 'Scope Change' (S:C), meaning the attacker can move beyond the Sales Offline component to impact other parts of the E-Business Suite environment. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle Sales Offline (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published by Oracle and NVD