Executive brief
Oracle E-Business Suite Secure Enterprise Search, a tool used by organizations to search across enterprise data, contains a vulnerability in its Search Integration Engine. An attacker with basic user credentials can exploit this over the network to view, modify, or delete certain business data. This could lead to unauthorized data manipulation or the exposure of sensitive internal information.
Technical details
This vulnerability exists in the Search Integration Engine component of Oracle E-Business Suite Secure Enterprise Search. It is classified as an easily exploitable flaw that can be triggered by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized updates, insertions, or deletions of a subset of data, as well as unauthorized read access to specific data sets. The vulnerability has a CVSS 3.1 base score of 5.4, reflecting impacts on confidentiality and integrity but not availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle E-Business Suite Secure Enterprise Search 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.