Executive brief
Oracle User Management is a core identity and access control component within Oracle E-Business Suite, which manages user accounts and permissions across enterprise financial and operational systems. A flaw in the internal operations component allows a low-privileged attacker with network access to escalate privileges and fully compromise the system, potentially gaining administrative control over user accounts and system access across the entire E-Business Suite deployment.
Technical details
This is a privilege escalation vulnerability in the Internal Operations component of Oracle User Management. The flaw is easily exploitable and requires only low-privilege user credentials and network HTTP access (no authentication bypass needed, but prior access required). Successful exploitation allows an attacker to escalate privileges and achieve complete compromise of the User Management system, affecting confidentiality, integrity, and availability. The vulnerability affects Oracle E-Business Suite versions 12.2.6 through 12.2.15. Oracle has released patches; confirmation of patch availability and detailed remediation guidance should be obtained from Oracle security advisories.
Affected products
- Oracle E-Business Suite 12.2.6 to 12.2.15
Timeline
- 2026-09-15: disclosed