Risk: Medium
An input validation vulnerability has been discovered in Oracle's E-Business Suite, which could permit Cross-Site Scripting attacks if successfully exploited.
An attacker can create a specially crafted URL, which will cause arbitrary scripting code to be executed by their target's browser, in order to access cookies - including authentication cookies.
A fix has been issued by Oracle and is available from http://www.oracle.com