Executive brief
A vulnerability exists in the Oracle Subledger Accounting component of the Oracle E-Business Suite, which is used by organizations to manage financial records and accounting data. A low-privileged user could potentially take full control of the accounting system, leading to the unauthorized access, modification, or deletion of sensitive financial information. While the attack is complex to execute, a successful exploit could result in a total compromise of the application's integrity and availability.
Technical details
This vulnerability is located in the Internal Operations component of Oracle Subledger Accounting (part of Oracle E-Business Suite). It is classified under improper privilege management and access control (CWE-269, CWE-284). An attacker with low-level credentials can exploit this flaw over the network via HTTP. Although the attack complexity is high, a successful exploit allows for a complete takeover of the Subledger Accounting product, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.
Affected products
- Oracle Subledger Accounting 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published