Executive brief
A vulnerability exists in the Bill Issues component of Oracle Bills of Material, a module within the Oracle E-Business Suite used for managing manufacturing product structures. An attacker with basic user access can exploit this flaw over the network to gain full control over the Bills of Material system. This could lead to the unauthorized modification of manufacturing data, theft of proprietary product designs, or disruption of production operations.
Technical details
A high-severity vulnerability in the Oracle Bills of Material component of Oracle E-Business Suite (specifically the 'Bill Issues' module) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific CWE is not detailed in the advisory, the CVSS vector indicates high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H) without requiring user interaction. Affected versions range from 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Bills of Material (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD entry published