Executive brief
Oracle iSupport, a customer service portal within the Oracle E-Business Suite, contains a vulnerability in its Call Back component. An authorized user with low-level permissions could exploit this flaw to view, modify, or delete certain customer support data. This could lead to unauthorized changes to service records or the exposure of sensitive support information.
Technical details
A vulnerability exists in the Call Back component of Oracle iSupport (part of Oracle E-Business Suite) affecting versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized 'update, insert, or delete' operations on a subset of iSupport data, as well as unauthorized read access to specific data sets. The vulnerability is tracked as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle iSupport 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released