Executive brief
A vulnerability exists in the WebUI component of Oracle Product Workbench, a tool within the Oracle E-Business Suite used for managing product data and lifecycles. An attacker with basic user credentials can remotely access the system to view, modify, or delete sensitive product information. Additionally, an exploit could disrupt business operations by causing a partial service outage of the workbench interface.
Technical details
A vulnerability in the WebUI component of Oracle Product Workbench (part of Oracle E-Business Suite) allows for unauthorized data manipulation and disclosure. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read, insert, update, or delete a subset of data accessible to the Product Workbench, and can also result in a partial denial of service (DoS). The affected versions range from 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Product Workbench 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update (CPU) published