Executive brief
Oracle Financials for Asia/Pacific, a core financial management module within Oracle E-Business Suite, contains a vulnerability that allows low-privileged attackers to gain unauthorized access to sensitive financial data and modify or delete critical records. An attacker with basic network access can exploit this flaw to view confidential financial information, alter transaction records, and temporarily disrupt financial operations without any special technical barriers.
Technical details
This is an authorization/access control vulnerability in the Oracle Financials for Asia/Pacific component (part of Oracle E-Business Suite) affecting versions 12.2.8 through 12.2.15. The vulnerability allows a low-privileged, authenticated user with network access via HTTP to bypass authorization controls and gain unauthorized access to critical financial data and operations. An attacker can create, delete, or modify financial records beyond their intended permissions, and achieve a partial denial of service against the application. The attack requires valid credentials but no user interaction or elevated privilege level. Patch status and detailed remediation steps should be available from Oracle's security updates.
Affected products
- Oracle E-Business Suite 12.2.8 to 12.2.15
Timeline
- 2026-09-15: disclosed