Executive brief
Oracle E-Business Suite includes a Marketing module with an Audience management component that has a vulnerability allowing low-privileged users to gain unauthorized access to sensitive customer data. An attacker with basic network access and limited user credentials can exploit this flaw to view confidential information that the Marketing application manages, potentially exposing customer records and business-critical data across connected systems.
Technical details
This is a confidentiality vulnerability in the Audience component of Oracle E-Business Suite Marketing (versions 12.2.3–12.2.15). The vulnerability is easily exploitable and requires only low privileges and network access via HTTP; no user interaction is needed. An authenticated attacker can bypass authorization controls to access critical or all data managed by Oracle Marketing. Although the vulnerability exists in Marketing, its impact extends beyond that product (scope change), potentially compromising additional connected E-Business Suite components. The CVSS 3.1 score of 7.7 reflects high confidentiality impact with no integrity or availability impact.
Affected products
- Oracle E-Business Suite Marketing 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed