Executive brief
Oracle XML Gateway, a component of Oracle E-Business Suite used for enterprise data integration and messaging, contains a vulnerability that allows authenticated users with network access to access confidential business data and disrupt service availability. An attacker could exploit this to steal critical corporate information or temporarily take the system offline, impacting business operations and data security.
Technical details
This is an easily exploitable vulnerability in the Install component of Oracle XML Gateway (versions 12.2.3–12.2.15) that requires low privilege account and network access via HTTP. The vulnerability allows an authenticated attacker to gain unauthorized access to sensitive data stored in the XML Gateway and cause partial denial of service. The attack vector is network-based with low complexity and no user interaction required. Successful exploitation results in high confidentiality impact (full access to XML Gateway data) and low availability impact (partial DOS).
Affected products
- Oracle XML Gateway 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed