Executive brief
A security vulnerability exists in the Oracle Application Object Library, a core component of the Oracle E-Business Suite used for managing application data and security. A low-privileged user with access to the underlying system could exploit this flaw to gain unauthorized access to sensitive business information. This could lead to a significant breach of confidentiality across multiple integrated Oracle products.
Technical details
This vulnerability affects the Core component of the Oracle Application Object Library in Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a local confidentiality breach where an attacker with low-privileged access to the infrastructure hosting the library can compromise the component. The exploit is characterized by a 'scope change,' meaning the impact extends beyond the Application Object Library to other integrated products. Successful exploitation results in unauthorized access to critical data or complete access to all data accessible by the library. The vulnerability is easily exploitable and does not require user interaction.
Affected products
- Oracle Application Object Library 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
- 2026-07-21: disclosed: CVE-2026-61111 was published to the NVD.