Unauthenticated Access Vulnerability in Oracle E-Business Suite by Oracle
CVE-2026-21972
5.3MEDIUM
What is CVE-2026-21972?
A vulnerability exists within Oracle Configurator, a component of Oracle E-Business Suite, that allows unauthenticated attackers with network access via HTTP to exploit the system. This flaw could lead to unauthorized access to certain data sets within Oracle Configurator, potentially compromising sensitive information. Organizations utilizing supported versions from 12.2.3 to 12.2.15 are especially at risk and should take immediate action to apply available security updates to secure their systems.
Affected Version(s)
Oracle Configurator 12.2.3 <= 12.2.15