Executive brief
Oracle XML Gateway is a component of Oracle E-Business Suite that handles XML-based data integration and electronic commerce transactions. A flaw allows an attacker with low-level credentials and network access to bypass authentication controls, potentially exposing sensitive business data and disrupting critical integration processes that depend on XML Gateway for order processing, invoicing, and inter-system communication.
Technical details
This vulnerability is an authentication bypass or authorization flaw in the Oracle XML Gateway install component (versions 12.2.3–12.2.15) that allows a low-privileged attacker with network access via HTTP to gain unauthorized access to sensitive data and trigger a partial denial of service. The attack requires valid credentials (low privilege level) but no user interaction, indicating the flaw exists in the authentication or access control logic of the gateway. An attacker can read critical data accessible through XML Gateway and degrade service availability. Patches should be available from Oracle's Critical Patch Update program.
Affected products
- Oracle XML Gateway 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed