EIP-2026-104032

PRE-CVE

Oracle E-Business Suite Financials 12 - 'jtfwcpnt.jsp' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104032. PoCs published by Joxean Koret.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Oracle E-Business Suite Financials by crafting malicious SQL queries via the 'query' parameter in 'jtfwcpnt.jsp'. The PoC shows how an attacker can execute arbitrary SQL commands, such as granting DBA privileges or deleting records, without authentication.

Description

Oracle E-Business Suite Financials 12 - 'jtfwcpnt.jsp' SQL Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by Joxean Koret · textremotemultiple
https://www.exploit-db.com/exploits/33839

This exploit demonstrates an SQL injection vulnerability in Oracle E-Business Suite Financials by crafting malicious SQL queries via the 'query' parameter in 'jtfwcpnt.jsp'. The PoC shows how an attacker can execute arbitrary SQL commands, such as granting DBA privileges or deleting records, without authentication.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Oracle E-Business Suite 12
No auth needed
Prerequisites: Network access to the target Oracle E-Business Suite instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026