Executive brief
Oracle E-Business Suite Financials is a financial management system used by enterprises to handle accounting, reporting, and transaction processing. A vulnerability in its Common Components allows low-privileged network attackers to view, create, delete, or modify financial data without proper authorization, potentially exposing or corrupting critical business records.
Technical details
This is an authorization bypass vulnerability in the Oracle Financials Common Modules component of E-Business Suite. The flaw allows a low-privileged attacker with network access via HTTP to escalate privileges and gain unauthorized access to sensitive financial data. The vulnerability requires authentication (PR:L) but does not require user interaction, and can be exploited over the network to achieve both confidentiality and integrity impacts. Affected versions are 12.2.3 through 12.2.15. Patch availability should be confirmed through Oracle's official security advisories.
Affected products
- Oracle E-Business Suite Financials Common Modules 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed