Executive brief
A vulnerability exists in the Internal Operations component of Oracle's maintenance and repair software within the E-Business Suite. This software is typically used by organizations to manage complex asset maintenance and logistics. An attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify records, potentially disrupting operations or compromising proprietary information.
Technical details
This vulnerability affects the Internal Operations component of Oracle Complex Maintenance, Repair and Overhaul (versions 12.2.3 through 12.2.15). It is an unauthenticated, network-based attack via HTTP. While the attack complexity is rated as high, a successful exploit results in a scope change (S:C), meaning the impact can extend beyond the immediate component to other parts of the Oracle E-Business Suite. Attackers can achieve unauthorized read access to all accessible data and unauthorized update/delete access to a subset of data. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle E-Business Suite (Complex Maintenance, Repair and Overhaul) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released