Executive brief
A vulnerability exists in the Core component of the Oracle Application Object Library, which is a foundational part of the Oracle E-Business Suite used for managing business applications. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could lead to a significant breach of confidentiality, exposing critical corporate information or all data accessible by the library.
Technical details
A vulnerability in the Core component of the Oracle Application Object Library within Oracle E-Business Suite (versions 12.2.3 through 12.2.15) allows for unauthorized data access. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a high confidentiality impact, potentially allowing the attacker to read all data accessible to the Application Object Library. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting its remote accessibility and lack of required privileges. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Application Object Library (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD record published