Executive brief
A critical vulnerability exists in the Oracle Internet Procurement Connector, a component of the Oracle E-Business Suite used for managing procurement operations. An attacker can exploit this flaw over the network without needing a username or password to gain full access to sensitive procurement data. This could lead to the unauthorized viewing, modification, or deletion of critical business records, potentially disrupting supply chain operations and compromising financial integrity.
Technical details
A vulnerability in the Internal Operations component of the Oracle Internet Procurement Connector (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation grants the attacker the ability to create, delete, or modify all data accessible to the connector, as well as complete read access to that data. The vulnerability affects versions 12.2.3 through 12.2.15. While the specific CWE is not identified in the advisory, the impact is high for both confidentiality and integrity.
Affected products
- Oracle Internet Procurement Connector (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory: Oracle Critical Patch Update May 2026 released