Executive brief
A vulnerability exists in the Audience component of Oracle Marketing, a tool used by businesses to manage customer segments and marketing campaigns. An employee or user with low-level access could exploit this flaw to view, modify, or delete marketing data they are not authorized to see. Additionally, an attacker could disrupt the service, causing partial outages that impact marketing operations.
Technical details
This vulnerability affects the Audience component of Oracle Marketing within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that can be triggered over the network via HTTP. An attacker requires low-level privileges (authenticated access) to exploit the vulnerability. Successful exploitation allows for unauthorized 'update, insert, or delete' access to a subset of data, unauthorized read access to certain records, and the ability to trigger a partial denial of service (DoS). The issue is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Marketing 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory