Executive brief
Oracle Product Hub, a component of the Oracle E-Business Suite used for managing centralized product information, contains a security vulnerability. An attacker with low-level user credentials can exploit this flaw over the network to view, modify, or delete certain product data. Additionally, an exploit could cause a partial service disruption, impacting the availability of the product catalog for other users.
Technical details
A vulnerability exists in the Item Catalog component of Oracle Product Hub (versions 12.2.3 through 12.2.15). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows for unauthorized read, update, insert, or delete access to a subset of data within the Product Hub. Furthermore, the vulnerability can be leveraged to cause a partial denial of service (DoS). The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Product Hub (Item Catalog) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory