Executive brief
Oracle E-Business Suite is a comprehensive enterprise resource planning system used by organizations to manage business operations and customer relations. A vulnerability in the Applications Framework's Personalization component allows a low-privilege attacker with network access to fully compromise the system, potentially leading to unauthorized access to critical business data, manipulation of financial records, or complete system takeover.
Technical details
This is a privilege escalation vulnerability in the Oracle Applications Framework Personalization component, affecting versions 12.2.9 through 12.2.15. The vulnerability is easily exploitable and requires only network access via HTTP and low-level privileges, with no user interaction needed. An attacker can achieve complete system compromise, including reading sensitive data, modifying system configuration and business records, and disrupting availability. The CVSS 3.1 score of 8.8 reflects high impact across confidentiality, integrity, and availability. Patch details have not yet been publicly disclosed.
Affected products
- Oracle E-Business Suite 12.2.9–12.2.15
Timeline
- 2026-09-15: disclosed