Executive brief
Oracle Customer Interaction History is a component within Oracle's E-Business Suite that stores customer communications and transaction records. A low-privileged attacker with network access can exploit this vulnerability to gain full control of the system, potentially compromising sensitive customer interaction data and disrupting business operations.
Technical details
This is an easily exploitable vulnerability in the Outcome-Result component of Oracle Customer Interaction History that allows a low-privileged attacker with network access via HTTP to achieve complete system compromise. The vulnerability enables unauthorized access and control over the affected application through a network-accessible interface without requiring user interaction. Successful exploitation results in full compromise of confidentiality, integrity, and availability of the Customer Interaction History service. The vulnerability affects versions 12.2.3 through 12.2.15 of Oracle E-Business Suite; patches should be available through Oracle's standard security update channels.
Affected products
- Oracle E-Business Suite 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed