Executive brief
Oracle Product Hub, a component of the Oracle E-Business Suite used for centralized product data management, contains a vulnerability in its Internal Operations component. A low-privileged attacker could exploit this flaw to gain full control over the Product Hub system. Such an attack could lead to the theft or modification of sensitive product data and potentially impact other integrated business systems.
Technical details
A vulnerability exists in the Internal Operations component of Oracle Product Hub (versions 12.2.3 through 12.2.15). The flaw is accessible via the network over HTTP and requires low-privileged authentication. While the attack complexity is rated as high, a successful exploit results in a scope change (S:C), meaning the attacker can impact components beyond the immediate Product Hub environment. This can lead to a total loss of confidentiality, integrity, and availability for the affected system. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.
Affected products
- Oracle Corporation Product Hub 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory