Executive brief
Oracle Loans is a core component of Oracle E-Business Suite used to manage loan and credit operations. A vulnerability in the Internal Operations component allows an authenticated user with low privileges to remotely manipulate, create, or delete critical loan data, and also trigger partial service disruptions. This could lead to unauthorized financial data changes, fraudulent transactions, and operational downtime affecting loan processing.
Technical details
This is an authorization and input validation flaw in the Oracle Loans product (Internal Operations component) affecting versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable via HTTP by a low-privileged, authenticated network attacker with no additional user interaction required. Successful exploitation allows unauthorized creation, deletion, or modification of critical loan data, and can cause partial denial of service. The CVSS 3.1 score of 7.1 reflects high integrity impact (data modification) and low availability impact. A patch or mitigation should be sought from Oracle's August 2026 security advisory.
Affected products
- Oracle E-Business Suite Loans 12.2.3 to 12.2.15
Timeline
- 2026-08-18: disclosed