Executive brief
Oracle XML Gateway is a critical middleware component within Oracle E-Business Suite used for enterprise data integration and messaging. A low-privileged attacker with network access can exploit this vulnerability to read sensitive business data and disrupt service availability, potentially affecting order processing, supply chain operations, and financial integrations.
Technical details
This is an easily exploitable vulnerability in the Oracle XML Gateway Install component affecting versions 12.2.3–12.2.15. The vulnerability allows a low-privileged, network-accessible attacker (via HTTP) to bypass authorization controls and access restricted data or cause partial denial of service. The attack requires valid authentication (PR:L) but no user interaction. Successful exploitation results in high confidentiality impact (unauthorized access to critical and all accessible data) and low availability impact (partial DoS). A patch is available via Oracle's September 2026 Critical Patch Update.
Affected products
- Oracle XML Gateway 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed