Executive brief
Oracle E-Business Suite's Sales module is a business-critical application used to manage customer orders and sales operations. A vulnerability in the Internal Operations component allows a low-privileged attacker with network access to take complete control of the Sales system, compromising confidentiality, integrity, and availability of sales data and operations.
Technical details
This is a privilege escalation vulnerability in the Oracle E-Business Suite Sales product (versions 12.2.3–12.2.15), located in the Internal Operations component. The vulnerability is difficult to exploit and requires an authenticated network attacker with low privileges to reach the affected component via HTTP. Successful exploitation enables complete takeover of the Sales system, potentially granting access to sensitive customer data, order information, and operational capabilities. The CVSS 3.1 score of 7.5 reflects high impacts across confidentiality, integrity, and availability. Patch availability should be confirmed via Oracle's official security advisory.
Affected products
- Oracle E-Business Suite 12.2.3 through 12.2.15
Timeline
- 2026-08-18: disclosed