Executive brief
Oracle iSupplier Portal, a tool used by businesses to manage communication and transactions with their suppliers, contains a security vulnerability in its Internal Operations component. A low-privileged attacker could potentially gain unauthorized access to a limited amount of sensitive data. While the risk is present, the vulnerability is considered difficult to exploit and requires the attacker to already have basic access to the system.
Technical details
This vulnerability exists within the Internal Operations component of Oracle iSupplier Portal (part of Oracle E-Business Suite). It is classified as an information disclosure bug that allows a low-privileged attacker to perform unauthorized read operations on a subset of accessible data. The attack vector is network-based via HTTP, but the exploit complexity is rated as high, suggesting specific conditions or timing are required for a successful compromise. The vulnerability affects supported versions 12.2.3 through 12.2.15. Remediation information is typically provided via Oracle's Critical Patch Update (CPU) program.
Affected products
- Oracle Corporation iSupplier Portal 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial advisory published by Oracle and NVD.