Executive brief
A vulnerability exists in Oracle iSetup, a tool used within the Oracle E-Business Suite for migrating and reporting on business data. An attacker with basic user access can exploit this flaw to take full control of the iSetup component. This could lead to unauthorized access to sensitive financial reports, data manipulation, or a complete disruption of the data migration service.
Technical details
This vulnerability in Oracle iSetup (part of Oracle E-Business Suite) is classified under improper privilege management and authentication bypass (CWE-269, CWE-287, CWE-306). It affects the General Ledger Update Transform and Reports components. An attacker with low-privileged user credentials can exploit the flaw over the network via HTTP without any user interaction. Successful exploitation allows for a complete takeover of the iSetup product, impacting confidentiality, integrity, and availability. The issue affects versions 12.2.3 through 12.2.15 and was addressed in the June 2026 Oracle Critical Patch Update.
Affected products
- Oracle iSetup 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published