Executive brief
Oracle Alert is a notification component within Oracle E-Business Suite, a widely-used enterprise resource planning system. A low-privileged network attacker can exploit a vulnerability in the Alert product to gain complete control over the Alert component, potentially compromising confidential business data, disrupting operations, or manipulating critical notifications sent across the organization.
Technical details
A network-exploitable vulnerability in the Oracle Alert product (component: Internal Operations) allows a low-privileged authenticated attacker to achieve complete compromise via HTTP. The vulnerability requires network access and valid user credentials but does not require user interaction. Successful exploitation results in full takeover of the Alert component, granting the attacker high-impact control over confidentiality, integrity, and availability of alert functionality. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15, and patches should be available from Oracle's security releases.
Affected products
- Oracle E-Business Suite 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed