Executive brief
A vulnerability exists in the Internal Operations component of Oracle Lease and Finance Management, a tool used by businesses to manage complex financial leasing lifecycles. A remote attacker with basic user credentials could exploit this flaw to gain full control over the application. This could lead to the unauthorized disclosure of sensitive financial data, modification of records, or a complete disruption of leasing operations.
Technical details
This vulnerability affects the Internal Operations component of Oracle Lease and Finance Management within the Oracle E-Business Suite. It is classified as a high-complexity exploit (AC:H), meaning successful exploitation may depend on specific configurations or timing conditions. An attacker requires network access via HTTP and low-privileged user credentials (PR:L) to execute the attack. If successful, the vulnerability allows for a complete compromise of the product's confidentiality, integrity, and availability, effectively resulting in a full takeover of the affected component. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Lease and Finance Management 12.2.11-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.