Executive brief
Oracle Customer Care, a component of the Oracle E-Business Suite used for managing customer interactions and internal operations, contains a vulnerability that allows for a complete system takeover. An attacker with basic user credentials can exploit this over the network to gain full control of the application. This could lead to the theft of sensitive customer data, unauthorized modification of records, and significant disruption to business operations.
Technical details
A vulnerability in the Internal Operations component of Oracle Customer Care (part of Oracle E-Business Suite) allows for a complete compromise of the application. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific vulnerability class (e.g., SQL injection, insecure deserialization) is not explicitly named in the advisory, the impact is rated as high for confidentiality, integrity, and availability, leading to a full takeover of the affected component. The issue affects supported versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Customer Care 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD