Executive brief
A vulnerability exists in the BI Publisher Integration component of Oracle E-Business Suite's Concurrent Processing product. This system is used by organizations to manage background tasks and generate business reports. An attacker with low-level user credentials could exploit this flaw to view, modify, or delete sensitive business data and potentially disrupt reporting services.
Technical details
A vulnerability in the BI Publisher Integration component of Oracle Concurrent Processing (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read, update, insert, or delete a subset of data accessible to the Concurrent Processing service. Additionally, the vulnerability can be used to cause a partial denial of service (DoS). The issue affects versions 12.2.3 through 12.2.15 and was addressed in the July 2026 Oracle Critical Patch Update.
Affected products
- Oracle Corporation Concurrent Processing (BI Publisher Integration) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published