Executive brief
Oracle Customer Interaction History is a module of Oracle E-Business Suite used to store and manage customer interactions and transaction records. A vulnerability in the user interface allows a low-privileged internal user with network access to gain full control over the system, potentially exposing or modifying sensitive customer data and business records.
Technical details
This is a privilege escalation vulnerability in the Oracle Customer Interaction History user interface component, affecting versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable and requires network access via HTTPS and a low-privilege user account (no high-privilege credentials needed). An authenticated attacker can exploit this flaw to achieve full system compromise with confidentiality, integrity, and availability impacts. Oracle has released a security patch as part of its standard security update cycle.
Affected products
- Oracle E-Business Suite Customer Interaction History 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed