Executive brief
A vulnerability exists in the Oracle iSupplier Portal, a platform used by businesses to manage communication and transactions with their global suppliers. An attacker could potentially gain unauthorized access to a limited amount of sensitive business data. While the risk of data exposure is present, the vulnerability is considered difficult to exploit and does not allow the attacker to modify data or disrupt services.
Technical details
This vulnerability affects the Internal Operations component of Oracle iSupplier Portal within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is characterized by a high attack complexity, meaning successful exploitation requires specific conditions or significant effort by the attacker. An unauthenticated attacker can exploit this via HTTP over the network to achieve unauthorized read access to a subset of data. The vulnerability impacts confidentiality but does not affect integrity or availability. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle iSupplier Portal 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory