Executive brief
Oracle Applications Framework is a core component of Oracle E-Business Suite, a widely-deployed enterprise resource planning system used to manage business operations and customer relations. A vulnerability in the Search Bean component allows a low-privileged attacker with network access to read, modify, or delete critical business data without authorization, potentially compromising financial records, customer information, and operational data across the entire system.
Technical details
This vulnerability in Oracle Applications Framework's Search Bean component is easily exploitable and requires only low-level privileges and network-accessible HTTP connectivity. An authenticated attacker can leverage this flaw to bypass access controls and achieve unauthorized data manipulation or exfiltration of sensitive information across all accessible Oracle Applications Framework data. The vulnerability affects E-Business Suite versions 12.2.3 through 12.2.15. While full technical details are limited by Oracle's advisory, the high integrity and confidentiality impact scores indicate a data access or injection-type vulnerability. Patches are available via Oracle's regular security update channels.
Affected products
- Oracle E-Business Suite 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed