NCSC | Security Advisories
Bekijk RSS-feed

Security Advisories

Download

Security Advisory; NCSC-2026-0310 [1.0.0]

Security Advisory
NCSC-2026-0310 [1.0.0]
Publicatie
19-08-2026 11:54 (Europe/Amsterdam)
Prioriteit
Normaal
Betreft
Kwetsbaarheden verholpen in Oracle E-Business Suite

Kenmerken

  • Exposure of Sensitive Information to an Unauthorized Actor

Omschrijving

Oracle heeft kwetsbaarheden verholpen in verschillende componenten van Oracle E-Business Suite, waaronder General Ledger, Payments, Workflow, Sales, Purchasing, Call Center Technology, en andere modules binnen de versies 12.2.3 tot en met 12.2.15.

De kwetsbaarheden in Oracle E-Business Suite versies 12.2.3 tot 12.2.15 stellen een aanvaller in staat met lage tot hoge privileges en netwerktoegang via HTTP of HTTPS om ongeautoriseerde acties uit te voeren. Deze acties omvatten het creƫren, verwijderen, wijzigen of lezen van kritieke data, het verkrijgen van ongeautoriseerde toegang tot gevoelige informatie, en in sommige gevallen het volledig overnemen van het systeem. Sommige kwetsbaarheden vereisen gebruikersinteractie, terwijl andere zonder authenticatie kunnen worden misbruikt. De impact strekt zich uit over vertrouwelijkheid, integriteit en beschikbaarheid van systemen en data. Daarnaast zijn er kwetsbaarheden die Denial-of-Service kunnen veroorzaken door het laten vastlopen of crashen van applicatiecomponenten. De kwetsbaarheden zijn aanwezig in diverse modules zoals financiƫle administratie, betalingsverwerking, workflowbeheer, verkoop, inkoop, klantenservice, en andere bedrijfsprocessen binnen de Oracle E-Business Suite.

Oplossingen

Oracle heeft updates uitgebracht om de kwetsbaarheden in Oracle E-Business Suite versies 12.2.3 tot en met 12.2.15 te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Referenties

CVE's

Producten

Oracle
E-Business Suite
Oracle Customer Care
Oracle MES for Process Manufacturing
Oracle Scripting
Oracle Teleservice
Oracle Workflow
Oracle iSupplier Portal
Oracle Corporation
Oracle Advanced Inbound Telephony
Oracle Applications DBA
Oracle Applications Platform Engineering
Oracle Bills of Material
Oracle Call Center Technology
Oracle Cash Management
Oracle Complex Maintenance, Repair and Overhaul
Oracle Customers Online
Oracle E-Business Tax
Oracle Email Center
Oracle Enterprise Asset Management
Oracle Financials Common Modules
Oracle Flow Manufacturing
Oracle General Ledger
Oracle HCM Common Architecture
Oracle HRMS (Netherlands)
Oracle Installed Base
Oracle Internet Procurement Connector
Oracle Labor Distribution
Oracle Landed Cost Management
Oracle Loans
Oracle Marketing
Oracle Marketing Encyclopedia System
Oracle Mobile Application Server
Oracle Operations Intelligence
Oracle Order Management
Oracle Partner Management
Oracle Payables
Oracle Payments
Oracle Payroll
Oracle Process Manufacturing Systems
Oracle Product Hub
Oracle Production Scheduling
Oracle Project Planning and Control
Oracle Proposals
Oracle Public Sector Financials (International)
Oracle Public Sector Human Resources
Oracle Purchasing
Oracle Risk Management
Oracle SDP Number Portability
Oracle Sales
Oracle Sales Foundation
Oracle Sales for Handhelds
Oracle Service Contracts
Oracle Service Fulfillment Manager
Oracle Shipping Execution
Oracle Telecommunications Billing Integrator
Oracle Trading Community
Oracle Transportation Execution
Oracle Warehouse Management
Oracle Work in Process
Oracle Yard Management
Oracle iRecruitment
Oracle iSetup

Disclaimer

The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions: NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein. NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory. This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings.