Executive brief
Oracle Sales Offline is a component of Oracle E-Business Suite used for managing sales operations. An unauthenticated attacker over the network can exploit this vulnerability to gain unauthorized access to sensitive sales data. Successful exploitation allows complete disclosure of confidential customer and operational information without requiring valid credentials.
Technical details
This is an information disclosure vulnerability in the Oracle Sales Offline component (Internal Operations module) of Oracle E-Business Suite. The vulnerability is easily exploitable by unauthenticated attackers with network access via HTTP, requiring no user interaction or special privileges. The root cause involves insufficient authentication/authorization controls in the affected component. A remote attacker can leverage this to read sensitive data accessible through Oracle Sales Offline, potentially exposing complete sales records and customer information. Affected versions are 12.2.3 through 12.2.15; Oracle has released security patches as part of their September 2026 Critical Patch Update.
Affected products
- Oracle E-Business Suite Sales Offline 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed