Executive brief
Oracle E-Business Suite's Payables module, a core financial application used by organizations to manage vendor payments and invoices, contains a vulnerability that allows a low-privileged network user to read, modify, or delete critical payment data. An attacker with legitimate system access could exploit this to alter payment records, create unauthorized transactions, or access sensitive vendor and financial information without proper authorization.
Technical details
The vulnerability exists in Oracle E-Business Suite Payables (versions 12.2.3 through 12.2.15) in the Internal Operations component and is remotely exploitable via HTTP. It allows a low-privileged, authenticated attacker with network access to perform unauthorized data operations (creation, modification, deletion) and information disclosure on Payables data. The issue involves inadequate access controls or validation checks, enabling privilege escalation or data access beyond the attacker's intended authorization level. The vulnerability requires valid credentials but does not require additional user interaction. A patch or update is expected from Oracle's security advisory (published 2026-08-18).
Affected products
- Oracle E-Business Suite Payables 12.2.3 through 12.2.15
Timeline
- 2026-08-18: disclosed