Executive brief
A vulnerability exists in the Common Components of Oracle E-Business Suite's Financials Common Modules, which are used for managing corporate financial data and business processes. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive financial records or modify data. This could lead to significant data breaches or the corruption of critical financial information across multiple integrated Oracle products.
Technical details
This vulnerability affects the Common Components of Oracle Financials Common Modules within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged user authentication and is accessible via the HTTP network protocol. The vulnerability is notable for a 'scope change' (S:C), meaning an exploit can impact components beyond the immediate Financials module. Successful exploitation allows for the unauthorized reading of all accessible data (high confidentiality impact) and the unauthorized modification, insertion, or deletion of some data (low integrity impact).
Affected products
- Oracle E-Business Suite Financials Common Modules 12.2.3-12.2.15
Timeline
- 2026-05-28: disclosed: Initial publication of CVE-2026-46820 by Oracle.
- 2026-05-28: advisory: NVD record published.