Executive brief
Oracle Proposals, a component of the Oracle E-Business Suite used for managing business proposals and sales documents, contains a security vulnerability. An attacker with low-level user credentials can exploit this flaw over the network to view, modify, or delete certain business data. Additionally, an exploit could cause a partial service outage, disrupting normal business operations.
Technical details
A vulnerability in the Proposals component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15) allows for unauthorized access and modification of data. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation can result in unauthorized read, update, insert, or delete access to a subset of Oracle Proposals data. It also allows an attacker to cause a partial denial of service (DoS). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Proposals 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed