Executive brief
A vulnerability in the Internal Operations component of Oracle Lease and Finance Management allows an attacker with basic user credentials to gain unauthorized access to sensitive financial data. This could lead to the unauthorized creation, deletion, or modification of critical business records within the Oracle E-Business Suite. Such an exploit poses a significant risk to financial data integrity and corporate compliance.
Technical details
This vulnerability affects the Internal Operations component of Oracle Lease and Finance Management (part of Oracle E-Business Suite) versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation grants the attacker unauthorized access to read, create, delete, or modify critical data or all data accessible to the application. The attack does not require user interaction and has high impacts on confidentiality and integrity, though it does not directly impact availability. Fixes are typically delivered via Oracle's Critical Patch Update (CPU) program.
Affected products
- Oracle Corporation Lease and Finance Management 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and security alert.
- 2026-07-21: advisory