Executive brief
A vulnerability exists in the Supply to Order Workbench component of Oracle E-Business Suite. This flaw allows an authorized user with low-level permissions to gain unauthorized access to sensitive business data. An attacker could potentially view, modify, or delete critical configuration and supply chain information, leading to significant data integrity issues and operational disruption.
Technical details
An improper access control vulnerability (CWE-284) exists in the Supply to Order Workbench component of Oracle Configure to Order (part of Oracle E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended restrictions to create, modify, or delete critical data, or gain full read access to all data accessible by the Configure to Order product. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle June 2026 Critical Patch Update for remediation details.
Affected products
- Oracle Configure to Order 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle published vendor advisory