Executive brief
A vulnerability exists in Oracle Advanced Pricing, a component of the Oracle E-Business Suite used by organizations to manage complex product pricing and promotions. An attacker with low-level user credentials could exploit this flaw over the network to gain unauthorized access to sensitive pricing data. This could result in the unauthorized viewing, modification, or deletion of critical business information, potentially impacting financial operations and data integrity.
Technical details
This vulnerability affects the Pricing Installation component of Oracle Advanced Pricing within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. The exploit enables unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized read access to all data within the Advanced Pricing module. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Advanced Pricing 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: NVD published the CVE record.