Executive brief
Oracle Applications Manager is a monitoring and diagnostics component of Oracle E-Business Suite used to manage enterprise resource planning systems. A vulnerability in the Oracle Diagnostics Interfaces component allows a low-privileged attacker with network access to compromise the entire Applications Manager system, potentially enabling unauthorized access to sensitive business data, system modification, and service disruption across the ERP environment.
Technical details
This is a low-complexity, easily exploitable privilege escalation vulnerability in the Oracle Diagnostics Interfaces component of Oracle Applications Manager. The vulnerability is reachable over the network via HTTPS by authenticated users (low privilege level required), requiring no user interaction. Successful exploitation grants an attacker complete control over the Applications Manager instance, with full confidentiality, integrity, and availability impact. Affected versions are 12.2.3 through 12.2.15; patch availability is not yet confirmed.
Affected products
- Oracle E-Business Suite Applications Manager 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed