Executive brief
A vulnerability exists in the Cost Planning component of Oracle Cost Management, a tool used by businesses to track and analyze manufacturing and supply chain costs. A high-privileged attacker could exploit this flaw to gain full access to sensitive financial data, modify or delete critical records, and cause partial service disruptions. While the impact on data integrity and confidentiality is high, the attack is considered difficult to execute and requires the attacker to already possess significant administrative permissions.
Technical details
This vulnerability affects the Cost Planning component of Oracle Cost Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a difficult-to-exploit flaw that requires an attacker to have high-level administrative privileges and network access via HTTP. Successful exploitation allows for the unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible by the Cost Management module. Additionally, an attacker can cause a partial denial of service (DoS). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Cost Management (Cost Planning) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory