Executive brief
A vulnerability exists in Oracle Product Hub, a centralized system used by businesses to manage product information across the enterprise. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain product data. Additionally, an exploit could cause a partial service disruption, potentially impacting supply chain operations or product data accuracy.
Technical details
A vulnerability in the Role Based Security component of Oracle Product Hub (part of Oracle E-Business Suite) allows for unauthorized data manipulation and disclosure. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read, insert, update, or delete a subset of data within the Product Hub, and can also result in a partial denial of service (DoS). The vulnerability affects versions 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Product Hub (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update (CPU) published