Executive brief
Oracle Report Manager is a critical reporting component within Oracle's E-Business Suite enterprise software used by large organizations to generate and manage business reports. A vulnerability in the Internal Operations component allows a low-privileged authenticated user to access sensitive business data and cause partial service disruption without proper authorization, potentially exposing confidential reports and operational data across the organization.
Technical details
This is an authentication/authorization bypass vulnerability in the Oracle E-Business Suite Report Manager product (component: Internal Operations). The vulnerability is easily exploitable and requires low privilege with network access via HTTPS; no user interaction is required. Successful exploitation allows an attacker to gain unauthorized access to critical data and achieve partial denial of service. The vulnerability affects versions 12.2.3 through 12.2.15. Patches are expected from Oracle's regular security update cycle.
Affected products
- Oracle E-Business Suite Report Manager 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed