Executive brief
Oracle Citizen Interaction Center, a component of the Oracle E-Business Suite used for managing public sector communications, contains a security vulnerability in its Internal Operations component. A high-privileged attacker could exploit this flaw to gain full access to sensitive data or modify critical records within the system. This could lead to significant data breaches or the unauthorized alteration of official citizen interaction records.
Technical details
A vulnerability exists in the Internal Operations component of Oracle Citizen Interaction Center (part of Oracle E-Business Suite) affecting versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows for the unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible by the Citizen Interaction Center. The vulnerability has a CVSS 3.1 base score of 6.5, primarily impacting confidentiality and integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Citizen Interaction Center (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published