Executive brief
Oracle Report Manager is a reporting component within Oracle E-Business Suite, a widely-used enterprise resource planning system. An unauthenticated network attacker with low privileges can exploit this vulnerability over HTTPS to gain complete control of the Report Manager system, potentially leading to unauthorized access to sensitive business data, modification of reports, or operational disruption.
Technical details
This vulnerability in the Oracle Report Manager component (part of E-Business Suite Internal Operations) is easily exploitable and allows a low-privileged attacker with network access to compromise the system via HTTPS without user interaction. The vulnerability affects versions 12.2.3 through 12.2.15. Successful exploitation results in complete takeover of the Report Manager, granting the attacker high-impact access to confidentiality, integrity, and availability. No patch availability information is provided in the advisory; customers should check Oracle's official security updates for remediation guidance.
Affected products
- Oracle E-Business Suite Report Manager 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed