Executive brief
Oracle E-Business Suite's Report Manager component contains a vulnerability that allows attackers with low-level access to view sensitive financial and operational data without proper authorization, and potentially disrupt reporting services. This puts critical business intelligence and compliance reports at risk of unauthorized disclosure or unavailability.
Technical details
The vulnerability is an authorization bypass in Oracle E-Business Suite Report Manager (Reports Security component) affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit weak access controls to gain unauthorized access to sensitive report data and cause partial denial of service. The attack requires valid credentials but no additional user interaction. Successful exploitation results in confidentiality breach (unauthorized data access) and availability impact (partial service disruption). Oracle has patched this vulnerability; customers should apply available security updates.
Affected products
- Oracle E-Business Suite 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed