Executive brief
A vulnerability exists in the Oracle Inventory Management component of the Oracle E-Business Suite, which is used by organizations to track and manage supply chain assets. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive business data. This could lead to a significant breach of confidential inventory records and potentially impact other integrated business systems.
Technical details
This vulnerability affects the Internal Operations component of Oracle Inventory Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is categorized as an information disclosure flaw that is easily exploitable over the network via HTTP. An attacker with low-level privileges can bypass intended access controls to view critical data or all data accessible to the Inventory Management module. Notably, the vulnerability involves a 'scope change' (S:C), meaning an exploit can impact security components beyond the immediate Inventory Management environment. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle Corporation Inventory Management 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory