Executive brief
Oracle iSupport, a customer service portal within the Oracle E-Business Suite, contains a security vulnerability in its Internal Operations component. An attacker could trick a legitimate user into performing an action that allows the attacker to modify, create, or delete critical business data. This could lead to unauthorized changes in customer support records or impact other integrated Oracle products.
Technical details
This vulnerability affects Oracle iSupport versions 12.2.3 through 12.2.15 within the Oracle E-Business Suite. It is an easily exploitable flaw in the Internal Operations component that can be triggered by an unauthenticated attacker over the network via HTTP. The exploit requires human interaction from a user other than the attacker (UI:R) and results in a scope change (S:C), meaning the impact can extend beyond iSupport to other integrated products. The primary impact is on integrity, allowing unauthorized creation, deletion, or modification of all data accessible through iSupport. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle iSupport 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released