Executive brief
Oracle Quality, a component of the Oracle E-Business Suite used for managing enterprise quality standards, contains a vulnerability in its Internal Operations component. A high-privileged user can exploit this flaw over the network to gain unauthorized access to sensitive data or modify records. This could lead to a significant breach of corporate data integrity and potential disruption of quality management processes.
Technical details
This vulnerability exists in the Internal Operations component of Oracle Quality within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring network access via HTTP and high-level administrative privileges. A successful exploit results in a 'scope change' (S:C), meaning the attacker can impact components beyond Oracle Quality itself. Impact includes unauthorized read access to all data, unauthorized modification or deletion of some data, and the ability to cause a partial denial of service. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Quality 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle and NVD publication.
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.