Executive brief
Oracle Treasury, a component of the Oracle E-Business Suite used for managing corporate financial operations and liquidity, contains a security vulnerability in its Internal Operations component. An attacker with basic user access to the network can exploit this flaw to view, modify, or delete sensitive financial data. This could lead to significant unauthorized changes to treasury records or the exposure of critical corporate financial information.
Technical details
This vulnerability exists in the Internal Operations component of Oracle Treasury within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve unauthorized creation, deletion, or modification of all accessible data within Oracle Treasury, as well as full read access to sensitive information. The vulnerability has high impacts on confidentiality and integrity but does not impact availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Oracle Treasury 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60963 was published to the NVD.