Executive brief
Oracle Public Sector Financials, a component of the E-Business Suite used by government organizations for financial management, contains a security vulnerability in its Internal Operations component. An attacker with existing low-level access to the network could potentially view sensitive financial data they are not authorized to see. While the risk is limited to unauthorized data reading and the attack is difficult to perform, it could lead to the exposure of internal organizational information.
Technical details
This vulnerability affects the Internal Operations component of Oracle Public Sector Financials within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a low-severity information disclosure bug that is difficult to exploit (High Attack Complexity). An attacker requires network access via HTTP and low-privileged credentials to successfully execute the attack. If successful, the attacker can obtain unauthorized read access to a limited subset of data managed by the Public Sector Financials product. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Public Sector Financials 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed