Executive brief
A vulnerability exists in the Oracle E-Business Suite's Public Sector Financials module, which is used by government entities to manage international financial operations. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive financial data. This could lead to a significant breach of confidential information and potentially impact other integrated business systems.
Technical details
This vulnerability is classified as an authorization flaw within the Oracle Public Sector Financials (International) component of Oracle E-Business Suite. It is easily exploitable by a low-privileged attacker with network access via HTTPS. The flaw is notable for a 'scope change' (S:C), meaning that an exploit can impact components beyond the immediate security scope of the affected module. Successful exploitation results in high confidentiality impacts, allowing unauthorized access to critical data or complete access to all data accessible by the module. Affected versions range from 12.2.6 through 12.2.15.
Affected products
- Oracle E-Business Suite (Public Sector Financials International) 12.2.6-12.2.15
Timeline
- 2026-05-28: disclosed: Initial disclosure by Oracle and NVD publication