Executive brief
Oracle Application Object Library, a core component of Oracle E-Business Suite, contains a vulnerability that allows unauthenticated attackers to access sensitive business data over the network. Attackers can exploit this flaw without authentication to gain unauthorized access to critical financial, operational, and customer data stored within the application, potentially exposing confidential business information.
Technical details
This is an easily exploitable vulnerability in the Core component of Oracle Application Object Library affecting versions 12.2.3 through 12.2.15. The vulnerability can be triggered by an unauthenticated attacker with network access via HTTP, requiring no user interaction or special privileges. Successful exploitation results in unauthorized disclosure of sensitive data accessible through Oracle Application Object Library, with confidentiality being the primary impact. The CVSS 3.1 Base Score is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating a network-based attack with low complexity and high confidentiality impact.
Affected products
- Oracle E-Business Suite Application Object Library 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed