Executive brief
Oracle E-Business Suite includes a Web Applications Desktop Integrator component that allows users to download files from the application. A vulnerability in the file download functionality allows an authenticated attacker with network access to bypass access controls and read sensitive business data stored in the system. An exploit could expose confidential financial records, customer information, or other critical company data.
Technical details
This is an authorization bypass vulnerability in the file download component of Oracle Web Applications Desktop Integrator. The vulnerability is easily exploitable and requires only low-privilege authentication and network access via HTTP; no user interaction is needed. A successful attack allows an attacker to access data they are not normally authorized to view, potentially exposing all critical information accessible through the application. The vulnerability affects supported versions 12.2.3 through 12.2.15. Patch availability and remediation guidance should be obtained from Oracle's security advisory.
Affected products
- Oracle E-Business Suite Web Applications Desktop Integrator 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed