Description
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in takeover of Oracle iSetup. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle iSetup product, specifically the General Ledger Update Transform and Reports components. It allows a low‑privileged attacker with network access through HTTP to compromise the system, leading to a full takeover of Oracle iSetup. This flaw arises from improper access control (CWE‑284) and results in confidentiality, integrity, and availability impacts, as reflected in the CVSS 3.1 vector

Affected Systems

Affected are Oracle E‑Business Suite installations using Oracle iSetup versions 12.2.3 through 12.2.15. Oracle customers deploying any of these releases with the General Ledger Update Transform or Reports components are at risk.

Risk and Exploitability

The CVSS base score of 8.8 signals a high severity vulnerability, though the EPSS score of <1% suggests a very low current exploitation probability. The attack can be conducted over the public network via HTTP with only low privileges, and the lack of listing in the KEV database indicates no publicly known exploits, but the potential impact warrants immediate attention.

Generated by OpenCVE AI on June 17, 2026 at 19:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that upgrades Oracle iSetup to a patched release, ensuring the General Ledger Update Transform and Reports components are fully patched.
  • Restrict network exposure by blocking or filtering HTTP access to Oracle iSetup, using firewall rules or a proxy that enforces authentication and connection limits.
  • Monitor application and web server logs for anomalous HTTP requests targeting iSetup endpoints, and investigate any unauthorized access attempts promptly.

Generated by OpenCVE AI on June 17, 2026 at 19:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in takeover of Oracle iSetup. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle isetup
CPEs cpe:2.3:a:oracle:isetup:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isetup
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-16T19:27:57.331Z

Reserved: 2026-05-18T15:55:10.312Z

Link: CVE-2026-46937

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T04:00:02Z

Weaknesses

No weakness.