Executive brief
A security vulnerability exists in the Oracle Application Object Library, a core component of the Oracle E-Business Suite used for managing application data and security. An attacker with low-level access to the corporate network could exploit this flaw to take full control of the library. This could lead to unauthorized access to sensitive business data, disruption of operations, and a total compromise of the affected application environment.
Technical details
This vulnerability resides in the DB Privileges component of the Oracle Application Object Library within Oracle E-Business Suite. It is classified as a high-complexity exploit that allows a low-privileged attacker with network access via HTTP to compromise the component. Successful exploitation can result in a complete takeover of the Oracle Application Object Library, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.3 through 12.2.15. Oracle has addressed this issue in the July 2026 Critical Patch Update.
Affected products
- Oracle Application Object Library (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed