Executive brief
A high-privileged attacker with network access can exploit a difficult-to-reach vulnerability in Oracle Application Object Library (a core component of Oracle E-Business Suite) to gain complete control over the system. Successful exploitation could lead to full compromise of the EBS environment, affecting confidentiality, integrity, and availability of financial, HR, and other mission-critical business data stored within the enterprise suite.
Technical details
This is a scope-change vulnerability in Oracle Application Object Library (Core component) affecting E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability requires high privileges and network access via HTTP to exploit, making it difficult to weaponize in practice. Successful attacks result in complete takeover of the Application Object Library component with cascading impact to other EBS systems. The exact vulnerability class is not disclosed in the advisory, but the CVSS vector indicates high impacts across confidentiality, integrity, and availability. No patch availability is stated in the provided information; affected organizations should consult Oracle's critical patch updates.
Affected products
- Oracle E-Business Suite Application Object Library 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed