Executive brief
A vulnerability exists in Oracle Landed Cost Management, a tool used by businesses to calculate the total cost of goods including shipping and duties. An attacker with basic user access can exploit this flaw to view, modify, or delete sensitive financial and operational data. This could lead to significant data breaches or the corruption of critical business records.
Technical details
This vulnerability affects the Internal Operations component of Oracle Landed Cost Management within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that can be triggered over the network via HTTP. An attacker requires low-level privileges (authenticated user) to execute the exploit. Successful exploitation allows for unauthorized creation, deletion, or modification of all data accessible to the Landed Cost Management module, as well as full read access to that data. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability.
Affected products
- Oracle Corporation Landed Cost Management 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published