Executive brief
A vulnerability exists in the Oracle Supply Chain Trading Connector, a component of the Oracle E-Business Suite used to manage business-to-business communications and collaboration history. An attacker with basic user credentials could exploit this flaw over the network to gain unauthorized access to sensitive business data. This could lead to the exposure of critical supply chain information and proprietary trading history.
Technical details
An information disclosure vulnerability exists in the Collaboration History component of the Oracle Supply Chain Trading Connector (Oracle E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended access controls to read critical data or all data accessible to the connector. The vulnerability affects versions 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation instructions.
Affected products
- Oracle Supply Chain Trading Connector 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory