Executive brief
Oracle Customer Interaction History is a data management component within Oracle E-Business Suite used to store and retrieve customer interaction records. A network-accessible vulnerability allows low-privileged users to read sensitive customer data without authorization, potentially exposing confidential business information and customer records across the entire system.
Technical details
This is an unauthorized data access vulnerability in the Outcome-Result component of Oracle Customer Interaction History. The vulnerability is easily exploitable over HTTP by an authenticated attacker with low privilege level and network access, requiring no user interaction. Successful exploitation results in unauthorized read access to critical customer interaction data, with a scope change indicating potential impact to other connected Oracle E-Business Suite products. The vulnerability affects versions 12.2.3 through 12.2.15 of Oracle Customer Interaction History.
Affected products
- Oracle E-Business Suite Customer Interaction History 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed