Executive brief
Oracle Site Hub, a component of Oracle E-Business Suite used for internal operations and data management, contains a vulnerability allowing low-privileged attackers with network access to create, delete, or modify critical business data. Exploitation can also expose sensitive information stored within the system, potentially impacting data integrity and confidentiality across business-critical operations.
Technical details
The vulnerability in Oracle Site Hub (component: Internal Operations) is easily exploitable and affects versions 12.2.3 through 12.2.15. The flaw requires only low-privilege authentication and network access via HTTP; no user interaction is needed. A successful attack allows an attacker to achieve unauthorized creation, deletion, or modification of critical data as well as read access to a subset of accessible data, resulting in high integrity and partial confidentiality impact. Patch availability has not been confirmed from the reference material provided.
Affected products
- Oracle E-Business Suite Site Hub 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed