Executive brief
A vulnerability exists in the Import and Export component of Oracle Learning Management, a tool used by organizations to manage employee training and development. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive corporate training data. This could lead to a significant breach of confidential information stored within the Oracle E-Business Suite environment.
Technical details
This vulnerability in Oracle Learning Management (part of Oracle E-Business Suite) affects the 'Import And Export' component. It is classified as an information disclosure flaw that is easily exploitable via HTTP. An attacker requires low-level privileges (authenticated user) to execute the attack over a network without user interaction. Successful exploitation allows the attacker to gain unauthorized read access to critical data or all data accessible to the Learning Management module. The issue is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Learning Management 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
- 2026-07-21: disclosed