Executive brief
Oracle iSetup is a configuration tool for Oracle E-Business Suite used to manage enterprise financial and operational data. This vulnerability allows a low-privileged attacker to gain complete control over the iSetup system via a network attack, potentially compromising sensitive financial records, reports, and system integrity across the entire EBS environment.
Technical details
This is a high-impact authentication or authorization bypass vulnerability in the General Ledger Update Transform and Reports component of Oracle iSetup. The vulnerability requires network access via HTTP and can be exploited by a low-privileged attacker, though exploitation is noted as difficult (CVSS AC:H). Successful exploitation results in complete takeover of the iSetup application, affecting confidentiality, integrity, and availability. The vulnerability impacts Oracle E-Business Suite versions 12.2.3 through 12.2.15, and patches are expected from Oracle's security team.
Affected products
- Oracle iSetup 12.2.3-12.2.15
Timeline
- 2026-08-18: disclosed