Executive brief
Oracle XML Gateway is a data integration component within Oracle E-Business Suite used to exchange information with external partners and systems. A vulnerability in the installation component allows an authenticated network attacker to bypass security controls, potentially exposing sensitive business data and disrupting gateway operations. This could enable unauthorized access to confidential customer, financial, or operational information stored within the system.
Technical details
The vulnerability exists in the Oracle XML Gateway installation component affecting versions 12.2.3 through 12.2.15 of Oracle E-Business Suite. It is easily exploitable and requires only low-privilege credentials and network access via HTTP, with no user interaction needed. A successful attack allows an attacker to gain unauthorized read access to critical data and cause partial denial of service to the XML Gateway. The attack vector is network-based with low complexity; patches or updates are expected from Oracle's security update process.
Affected products
- Oracle E-Business Suite XML Gateway 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed