Executive brief
A vulnerability exists in the Oracle Service Fulfillment Manager, a component of the Oracle E-Business Suite used to manage and automate service orders. An attacker with basic user access can exploit this flaw over the network to gain full access to sensitive business data. This could lead to the unauthorized viewing, modification, or deletion of critical service fulfillment records, potentially disrupting business operations and compromising customer information.
Technical details
This vulnerability affects the Fulfillment Engine component of Oracle Service Fulfillment Manager (Oracle E-Business Suite). It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. The vulnerability does not require user interaction. Successful exploitation grants the attacker unauthorized 'create, delete, or modification' access as well as 'read' access to all data accessible by the Service Fulfillment Manager. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N, indicating high confidentiality and integrity impacts but no impact on availability. Affected versions range from 12.2.3 through 12.2.15.
Affected products
- Oracle Service Fulfillment Manager 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published