Executive brief
Oracle E-Business Suite Loans is a financial management module used by enterprises to administer lending operations and loan portfolios. An attacker with low-level network access can exploit this vulnerability to read sensitive financial data, modify loan records, or delete transaction information, potentially causing financial data corruption and compliance violations.
Technical details
The vulnerability in the Oracle Loans product (component: Internal Operations) allows an authenticated attacker to bypass authorization controls and access restricted data or perform unauthorized modifications. The flaw is exploitable over the network via HTTP with low privileges and does not require user interaction. Successful exploitation grants unauthorized read access to confidential loan data and limited write access (update/insert/delete) to certain Loans-accessible data. The vulnerability affects E-Business Suite versions 12.2.3 through 12.2.15; patch availability and fix status depend on Oracle's Critical Patch Update releases.
Affected products
- Oracle E-Business Suite 12.2.3–12.2.15
Timeline
- 2026-08-18: disclosed