Executive brief
A vulnerability exists in Oracle Advanced Benefits, a component of the Oracle E-Business Suite used for managing employee benefits programs. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive organizational data. This could lead to a significant breach of confidential information stored within the benefits system.
Technical details
A vulnerability in the Internal Operations component of Oracle Advanced Benefits (part of Oracle E-Business Suite) allows for unauthorized data access. The flaw is categorized as an information disclosure vulnerability that can be exploited by a low-privileged attacker with network access via HTTP. Successful exploitation requires no user interaction and can result in the compromise of all accessible data within the Advanced Benefits module, impacting confidentiality. The affected version is 12.2.15, and the issue was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Corporation Oracle Advanced Benefits 12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: NVD published the CVE record.