Executive brief
Oracle E-Business Suite's Document Management and Collaboration product, a core file and collaboration tool in Oracle's enterprise resource planning suite, contains an authentication bypass vulnerability. An unauthenticated remote attacker can exploit this flaw over the network without user interaction, potentially gaining full administrative control over the system and accessing or modifying sensitive business documents and data.
Technical details
The vulnerability is an easily exploitable authentication bypass in the Internal Operations component of Oracle Document Management and Collaboration within E-Business Suite versions 12.2.3 through 12.2.15. The flaw allows an unauthenticated attacker with network access to reach the vulnerable HTTP interface and bypass authentication controls. A successful exploit grants complete system compromise, including confidentiality, integrity, and availability impacts. The attack requires no user interaction and can be triggered remotely via the network; Oracle has released patches for affected versions.
Affected products
- Oracle E-Business Suite Document Management and Collaboration 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed