Executive brief
Oracle E-Business Suite's Application Object Library component is vulnerable to unauthorized data access when accessed by a low-privileged user over the network via HTTP. An attacker with low privileges and network access can view sensitive business data and confidential information stored within the E-Business Suite, affecting the confidentiality of all data managed by this critical enterprise application component.
Technical details
This vulnerability in Oracle E-Business Suite's Core component of Application Object Library is an authorization or information disclosure flaw allowing low-privileged, authenticated users with network access via HTTP to read restricted data. The vulnerability has a CVSS 3.1 base score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), indicating network accessibility, low attack complexity, and requirement for low privilege authentication. Successful exploitation results in high-impact confidentiality loss—unauthorized access to critical data managed by the Application Object Library component. No information disclosure regarding patch availability is currently available.
Affected products
- Oracle E-Business Suite 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed