Executive brief
A vulnerability exists in the Oracle Installed Base component of the Oracle E-Business Suite, which is used by organizations to track and manage product lifecycles and customer assets. An attacker with basic user credentials could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. This could lead to the exposure of proprietary information or the corruption of critical asset management records.
Technical details
This vulnerability affects the 'Create Item Instance' component of Oracle Installed Base within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve high confidentiality impact, gaining access to all data within the component, and low integrity impact, allowing for unauthorized updates, insertions, or deletions of certain data. The vulnerability does not impact system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Installed Base 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory