Executive brief
The Oracle Marketing Encyclopedia System in E-Business Suite contains a vulnerability that allows low-privileged attackers with network access to gain unauthorized access to sensitive business data. An attacker can exploit this via standard HTTP requests to read critical information or fully compromise the system's data accessibility. The impact extends beyond the vulnerable component itself, potentially affecting other connected systems within the E-Business Suite environment.
Technical details
This is an authorization or access control vulnerability in the Oracle Marketing Encyclopedia System (a component of Oracle E-Business Suite) that is easily exploitable and requires low privileges with network access. The attack vector is HTTP-based with no user interaction needed. An authenticated (low-privileged) attacker can leverage a scope-change vulnerability to read highly sensitive data, potentially gaining unauthorized access to confidential business information stored in or accessible through the Marketing Encyclopedia System. The vulnerability affects versions 12.2.3 through 12.2.15, and patches are expected from Oracle's published security advisory (though the reference URL is currently unavailable).
Affected products
- Oracle E-Business Suite 12.2.3 to 12.2.15
Timeline
- 2026-08-18: disclosed