Executive brief
A vulnerability exists in Oracle Lease and Finance Management, a component of the Oracle E-Business Suite used by organizations to manage financial contracts and asset leasing. A high-privileged attacker could exploit this flaw to take full control of the application. This could lead to the unauthorized access, modification, or deletion of sensitive financial data and business operations.
Technical details
This vulnerability affects the Internal Operations component of Oracle Lease and Finance Management within Oracle E-Business Suite versions 12.2.14 and 12.2.15. It is classified as an easily exploitable flaw that requires high privileges (PR:H) but no user interaction. An attacker can exploit this over the network via HTTP to achieve a complete compromise of the application, impacting confidentiality, integrity, and availability. While the specific CWE is not provided in the advisory, the impact is described as a full system takeover. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Lease and Finance Management 12.2.14, 12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed