Executive brief
A vulnerability exists in the Oracle Public Sector Financials module of the Oracle E-Business Suite, which is used by government organizations to manage international financial operations. An attacker with basic user access to the network can exploit this flaw to take full control of the financial system. This could lead to the unauthorized viewing of sensitive financial data, modification of records, or a complete disruption of financial services.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the Authorization component of Oracle Public Sector Financials (International). It is easily exploitable by a low-privileged attacker who has network access via HTTP. The flaw allows for a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Oracle has addressed this in their June 2026 security update.
Affected products
- Oracle Corporation Public Sector Financials (International) 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published