Executive brief
Oracle Product Workbench, a component of the Oracle E-Business Suite used for managing product lifecycles and engineering data, contains a security vulnerability. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft, deletion, or modification of critical product information, potentially disrupting manufacturing or engineering operations.
Technical details
A vulnerability in the Security component of Oracle Product Workbench (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is classified as easily exploitable, requiring only low-privileged (PR:L) authentication and network access via HTTP (AV:N). Successful exploitation enables an attacker to achieve high impacts on confidentiality and integrity (C:H/I:H) by accessing or altering critical data within the Product Workbench. The vulnerability affects supported versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Product Workbench 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.