Executive brief
A vulnerability exists in the Core component of Oracle Advanced Supply Chain Planning, a tool used by businesses to manage complex logistics and production schedules. A high-privileged attacker could exploit this flaw over the network to gain full control of the application. This could lead to the unauthorized access, modification, or deletion of critical supply chain data, potentially disrupting business operations and manufacturing.
Technical details
This vulnerability affects the Core component of Oracle Advanced Supply Chain Planning within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a high-privileged attacker to gain unauthorized access via the HTTP protocol. Successful exploitation can result in a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The attack vector is network-based and does not require user interaction, though it does require high-level administrative privileges. Oracle addressed this issue in the July 2026 Critical Patch Update.
Affected products
- Oracle Corporation Advanced Supply Chain Planning 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date