Executive brief
A vulnerability exists in the Quality Workbench HTML component of Oracle E-Business Suite, which is used by organizations to manage quality control and compliance data. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive quality records. Additionally, the exploit can be used to disrupt the availability of the Quality Workbench system, potentially impacting manufacturing or compliance operations.
Technical details
This vulnerability affects the Quality Workbench HTML system within Oracle Quality, a component of Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation enables unauthorized read, update, insert, or delete access to a subset of data accessible to Oracle Quality. Furthermore, the vulnerability can be leveraged to cause a partial denial of service (DoS). The attack does not require user interaction and has a CVSS 3.1 base score of 6.3, reflecting impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Quality 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.