Executive brief
A vulnerability exists in the Internal Operations component of Oracle Financials Common Country, a module within the Oracle E-Business Suite used for managing regional financial requirements. An attacker with basic user access can exploit this flaw to view, modify, or delete sensitive financial data. This could lead to significant data breaches, financial record tampering, and loss of data integrity across the organization's financial systems.
Technical details
This vulnerability affects the Internal Operations component of Oracle Financials Common Country within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. The attack does not require user interaction. Successful exploitation grants the attacker high confidentiality and integrity impacts, enabling them to read, create, or modify critical data or all data accessible to the affected component. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Financials Common Country (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released