Executive brief
Oracle Proposals is a component within Oracle E-Business Suite used to manage business proposals and related operations. A vulnerability allows low-privilege network attackers to gain unauthorized access to sensitive proposal data and potentially impact other connected systems. Exploitation requires valid credentials but no additional user interaction, creating a direct path to data theft affecting business-critical information.
Technical details
This is an authorization or access control vulnerability in the Oracle Proposals component (Internal Operations module) of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable via HTTP by an authenticated attacker with low privileges, requiring no user interaction. Successful exploitation allows unauthorized access to critical proposal data within Oracle Proposals and may impact scope beyond the immediate component, affecting other E-Business Suite products. A patch or mitigation should be available from Oracle; consult the official Oracle security advisory for remediation options.
Affected products
- Oracle E-Business Suite Proposals 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed