Executive brief
A vulnerability exists in the Oracle Bills of Material component of the Oracle E-Business Suite, which is used by manufacturing organizations to manage product structures and manufacturing data. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive business data or modify critical manufacturing records. This could lead to significant data breaches or the corruption of essential operational information.
Technical details
This vulnerability affects the Internal Operations component of Oracle Bills of Material within Oracle E-Business Suite versions 12.2.13 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve high confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of all accessible data within the Bills of Material module. The vulnerability does not impact system availability or require user interaction. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Bills of Material 12.2.13-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-61327 was published to the NVD.