Executive brief
A vulnerability in the Internal Operations component of Oracle Product Hub could allow an authorized user with low-level permissions to take full control of the system. Oracle Product Hub is a centralized platform used by businesses to manage product data and lifecycle information across the enterprise. A successful exploit could lead to the total loss of data confidentiality, integrity, and service availability, potentially disrupting supply chain operations and exposing sensitive product specifications.
Technical details
A vulnerability exists in the Internal Operations component of Oracle Product Hub (part of Oracle E-Business Suite) affecting versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific vulnerability class (e.g., SQL injection, insecure deserialization) is not explicitly named in the advisory, the impact is rated as a complete compromise of confidentiality, integrity, and availability (takeover). No user interaction is required for exploitation. Organizations should refer to the Oracle Critical Patch Update for July 2026 for remediation instructions.
Affected products
- Oracle Product Hub 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD