Executive brief
A vulnerability exists in the Workflow Notification Mailer component of Oracle E-Business Suite, which handles automated business process communications. An unauthenticated attacker could potentially modify business data or cause a partial service disruption. While the impact is limited to data integrity and system availability, it could interfere with critical business workflows and notification delivery.
Technical details
This vulnerability affects the Workflow Notification Mailer component within Oracle Workflow (Oracle E-Business Suite). It is classified as difficult to exploit (High Attack Complexity) but can be triggered by an unauthenticated attacker with network access via the SMTP protocol. Successful exploitation allows an attacker to perform unauthorized updates, insertions, or deletions of certain data accessible to Oracle Workflow. Additionally, the flaw can be leveraged to cause a partial denial of service (DoS) affecting the availability of the workflow component. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Workflow 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published