Executive brief
A vulnerability exists in the Internal Operations component of Oracle Learning Management, a tool used by organizations to manage employee training and certifications. A low-privileged user can exploit this flaw over the network to gain unauthorized access to sensitive training data or modify critical records. This could lead to a significant breach of corporate data integrity and confidentiality within the E-Business Suite environment.
Technical details
A vulnerability in the Internal Operations component of Oracle Learning Management (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to create, delete, or modify all accessible data within the Learning Management module, as well as gain complete read access to sensitive information. The issue affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Learning Management 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication