Executive brief
A vulnerability exists in Oracle Price Protection, a component of the Oracle E-Business Suite used by organizations to manage price changes and supplier rebates. An attacker with basic user access to the corporate network could exploit this flaw to view sensitive business data. This could lead to the unauthorized exposure of critical financial or pricing information, potentially impacting competitive advantage or regulatory compliance.
Technical details
This vulnerability affects the Internal Operations component of Oracle Price Protection within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an information disclosure flaw that is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation does not require user interaction but allows the attacker to gain unauthorized access to critical data or complete access to all data accessible by the Oracle Price Protection module. The vulnerability has a CVSS 3.1 base score of 6.5, reflecting a high impact on confidentiality. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Price Protection 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published as part of Oracle Critical Patch Update (CPU) July 2026