Executive brief
A vulnerability exists in the Oracle Installed Base component of the Oracle E-Business Suite, which is used by organizations to track and manage product life cycles and customer assets. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive business data, including the ability to create, modify, or delete critical records. This could lead to significant data integrity issues and the exposure of proprietary asset information.
Technical details
This vulnerability affects the 'Create Item Instance' component of Oracle Installed Base within Oracle E-Business Suite versions 12.2.4 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation grants the attacker unauthorized capabilities to create, delete, or modify critical data, as well as full read access to all data accessible by the Oracle Installed Base module. The attack does not require user interaction and has a high impact on both confidentiality and integrity, though it does not directly impact service availability.
Affected products
- Oracle Corporation E-Business Suite (Oracle Installed Base) 12.2.4 - 12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update (CPU) published