Executive brief
Oracle Application Object Library, a core component of Oracle E-Business Suite used for enterprise application management, contains a vulnerability allowing unauthenticated attackers to access the system over the network. An attacker could modify, delete, or view sensitive business data stored within the system, impacting data integrity and confidentiality.
Technical details
This is a difficult-to-exploit vulnerability in the Oracle Application Object Library component (Core) affecting E-Business Suite versions 12.2.3 through 12.2.15. It allows unauthenticated attackers with network access via HTTP to bypass authentication controls and gain unauthorized access to data. The vulnerability enables attackers to perform unauthorized creation, deletion, or modification of critical data, as well as read access to sensitive information. A patch is expected to be available from Oracle; consult Oracle's security advisory for specific patch timing and version information.
Affected products
- Oracle E-Business Suite 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed