Executive brief
Oracle Cash Management is a financial module within Oracle E-Business Suite that handles cash transactions and fund management. A local privilege escalation vulnerability allows high-privileged users with server access to read or modify financial data without additional authorization, potentially leading to unauthorized transaction manipulation, data theft, or financial fraud.
Technical details
A privilege escalation vulnerability exists in the Internal Operations component of Oracle Cash Management within E-Business Suite. The vulnerability is easily exploitable by high-privileged attackers (such as administrators or system users) who have local access to the infrastructure hosting Oracle Cash Management. No user interaction is required. Successful exploitation allows unauthorized creation, deletion, or modification of critical financial data, as well as complete read access to all Cash Management data. The attack vector is local (AV:L), requires high privileges (PR:H), and has high impact on both confidentiality and integrity (C:H/I:H) with no availability impact.
Affected products
- Oracle E-Business Suite Cash Management 12.2.3 through 12.2.15
Timeline
- 2026-08-18: disclosed