Executive brief
A vulnerability exists in Oracle Advanced Pricing, a component of the Oracle E-Business Suite used by organizations to manage complex product pricing and promotions. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive pricing data. This could result in the theft of proprietary business information or the unauthorized modification and deletion of critical pricing records, potentially disrupting sales operations and financial reporting.
Technical details
This vulnerability affects the Pricing Installation component of Oracle Advanced Pricing within Oracle E-Business Suite. It is classified as an unauthorized data access and modification flaw that is easily exploitable via the network using HTTP. An attacker requires low-level privileges (authenticated user) to execute the exploit. Successful exploitation allows for the unauthorized reading of all accessible data (High Confidentiality impact) and the unauthorized update, insertion, or deletion of some data (Low Integrity impact). The vulnerability does not impact system availability. The issue is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Oracle Advanced Pricing 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication by Oracle and NVD
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released