Executive brief
A vulnerability exists in the Definition component of Oracle E-Business Intelligence, a tool used for business data analysis and reporting. A highly privileged attacker could potentially modify, insert, or delete certain business data, though this requires a legitimate user to perform a specific action. The risk is considered low because the attack is difficult to execute and requires significant existing access.
Technical details
This vulnerability affects the Definition component of Oracle E-Business Intelligence versions 12.2.3 through 12.2.15. It is classified as a low-impact integrity issue where a high-privileged attacker with network access via HTTP can perform unauthorized updates, insertions, or deletions of data. The attack is characterized by high complexity (AC:H) and requires human interaction (UI:R) from a person other than the attacker. The vulnerability does not impact data confidentiality or service availability. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle E-Business Intelligence 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory