Executive brief
A vulnerability exists in Oracle iSupport, a customer service and support module within the Oracle E-Business Suite. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive business data or modify critical information. While the attack is difficult to execute, a successful breach could lead to a significant loss of data confidentiality and integrity within the support system.
Technical details
This vulnerability affects the Internal Operations component of Oracle iSupport in Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a high-complexity attack (AC:H) that can be initiated by an unauthenticated attacker over the network via HTTP. Successful exploitation allows for the unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible within the iSupport module. The vulnerability has significant impacts on Confidentiality and Integrity but does not directly impact Availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle iSupport (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle released the Critical Patch Update (CPU) containing this advisory.
- 2026-07-21: disclosed: NVD published the CVE record.