Executive brief
Oracle E-Business Suite's Applications Framework component allows low-privileged users to access or modify business-critical data they should not be able to reach. An attacker with basic network access and limited user privileges can exploit this to steal confidential information or make unauthorized changes to financial records, customer data, or other sensitive business data stored in the system.
Technical details
This vulnerability exists in the Personalization component of Oracle Applications Framework within Oracle E-Business Suite versions 12.2.9 through 12.2.15. The flaw allows a low-privileged, network-connected attacker to bypass authorization controls via HTTP requests, resulting in unauthorized read access to sensitive data and limited write/update/delete capabilities. The attack requires valid user credentials but no special privileges or additional user interaction. An attacker can read confidential business data and modify certain records without proper authorization checks. No evidence of active exploitation has been reported.
Affected products
- Oracle E-Business Suite 12.2.9 to 12.2.15
Timeline
- 2026-09-15: disclosed