Executive brief
Oracle iSupport, a customer service and support module within the Oracle E-Business Suite, contains a vulnerability in its Internal Operations component. A high-privileged attacker could exploit this flaw to gain full control over the iSupport system. Such an attack could lead to a total loss of confidentiality, integrity, and service availability for the support platform.
Technical details
This vulnerability affects Oracle iSupport versions 12.2.3 through 12.2.15 within the Oracle E-Business Suite. The flaw exists in the Internal Operations component and is characterized by a high attack complexity, requiring the attacker to possess high-level administrative privileges. Exploitation occurs over the network via HTTP and does not require user interaction. A successful exploit allows for a complete takeover of the iSupport product, impacting confidentiality, integrity, and availability. Oracle has addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle iSupport 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released