Executive brief
A vulnerability exists in Oracle E-Business Intelligence, a suite used by organizations for business data analysis and reporting. A high-privileged attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify critical information. While the impact on data integrity and confidentiality is significant, the attack is considered difficult to perform and requires existing high-level administrative access.
Technical details
This vulnerability affects the Internal Operations component of Oracle E-Business Intelligence within the Oracle E-Business Suite. It is classified as a medium-severity issue with a CVSS score of 5.9, primarily impacting confidentiality and integrity. An attacker requires high privileges and network access via HTTP to exploit the flaw. The attack complexity is rated as high, suggesting that successful exploitation relies on specific environmental conditions or complex timing. If successful, an attacker can perform unauthorized creation, deletion, or modification of critical data, or gain full access to all data accessible by the E-Business Intelligence product. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle E-Business Intelligence 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released