Executive brief
Oracle E-Business Suite includes a User Management component that handles authentication and authorization for enterprise resource planning operations. A vulnerability in the Proxy User Delegation feature allows a low-privileged attacker to gain full control over the User Management system, potentially compromising confidentiality, integrity, and availability of critical business data and operations managed through the platform.
Technical details
This is a privilege escalation vulnerability in Oracle E-Business Suite's User Management component, specifically in the Proxy User Delegation feature. The vulnerability is easily exploitable and requires only low-level privileges and network access via HTTP; no user interaction is needed. An authenticated attacker can escalate their privileges to take over the entire User Management system, resulting in complete compromise of the affected component. The vulnerability affects versions 12.2.3 through 12.2.15, and patches are expected to be available through Oracle's critical patch update program.
Affected products
- Oracle E-Business Suite 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed