Executive brief
A critical vulnerability exists in Oracle Applications Manager, a tool used to manage and monitor the Oracle E-Business Suite environment. A low-privileged user can exploit this flaw over the network to gain full control of the management system. Because this component oversees broader business operations, a successful attack could allow an intruder to compromise other integrated systems and sensitive corporate data.
Technical details
A vulnerability in the Internal Operations component of Oracle Applications Manager (Oracle E-Business Suite) allows for improper privilege management and access control (CWE-269, CWE-284). The flaw is easily exploitable via HTTP by a low-privileged attacker with network access. Due to a scope change (S:C), an attacker who successfully compromises the Applications Manager can potentially impact additional products within the E-Business Suite ecosystem. This can result in a complete loss of confidentiality, integrity, and availability. Affected versions include 12.2.3 through 12.2.15.
Affected products
- Oracle Applications Manager (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date