Executive brief
A vulnerability exists in the Internal Operations component of Oracle Customers Online, a module within the Oracle E-Business Suite used for managing customer data. An attacker with low-level user credentials can exploit this flaw over the network to gain full access to sensitive customer information. This could result in the unauthorized viewing, modification, or deletion of critical business data, potentially leading to significant data breaches or operational disruption.
Technical details
A vulnerability in the Internal Operations component of Oracle Customers Online (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to create, delete, or modify critical data, as well as gain complete read access to all data accessible within the Customers Online module. The vulnerability affects versions 12.2.3 through 12.2.15. While the specific CWE is not identified in the advisory, the impact is limited to Confidentiality and Integrity (C:H/I:H) with no impact on Availability.
Affected products
- Oracle Corporation Customers Online (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update July 2026