Executive brief
Oracle E-Business Suite is an enterprise resource planning (ERP) system used by organizations to manage business finances and operations. A vulnerability in the Personalization component of the Applications Framework allows a high-privileged attacker to gain complete control over the system. This could lead to unauthorized access to sensitive financial and operational data, modification of records, and extended service outages.
Technical details
This vulnerability exists in the Personalization component of the Oracle Applications Framework within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is easily exploitable and requires network access via HTTP, high administrative privileges, and no user interaction to trigger. Successful exploitation allows an attacker with high privileges to compromise the entire Applications Framework, resulting in complete takeover of the system. The vulnerability impacts confidentiality, integrity, and availability of the affected system. Oracle has issued a security advisory addressing this issue.
Affected products
- Oracle E-Business Suite 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed: Vulnerability disclosed by Oracle