Executive brief
A vulnerability exists in the Internal Operations component of Oracle Inventory Management, a tool used by businesses to track and manage stock levels and supply chain logistics. An attacker with high-level administrative access to the underlying server could potentially disrupt the application's availability. This could lead to a partial service outage, though the complexity of the attack and the requirement for existing high-level access make it a low-risk issue for most organizations.
Technical details
This vulnerability affects the Internal Operations component of Oracle Inventory Management within the Oracle E-Business Suite, versions 12.2.3 through 12.2.15. It is classified as a local denial-of-service vulnerability that requires high privileges and is considered difficult to exploit (High Attack Complexity). An attacker must have existing logon access to the infrastructure where the software executes. Successful exploitation allows the attacker to cause a partial denial of service (DoS), impacting the availability of the Inventory Management system. No confidentiality or integrity impacts are reported. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Corporation Inventory Management 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and July 2026 CPU.