Executive brief
Oracle Demand Planning is a supply chain planning tool used to forecast demand and manage inventory across organizations. An authenticated attacker with network access can exploit this vulnerability to create, delete, or modify critical business data, or gain unauthorized read access to all data in the system—potentially compromising supply chain visibility and operational integrity across affected enterprises.
Technical details
This is a privilege escalation vulnerability in Oracle Demand Planning's Internal Operations component, affecting versions 12.1 and 12.2. The vulnerability is easily exploitable and requires only low-privileged network access via HTTP; no user interaction is needed. An authenticated attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as complete read access to all accessible data. The scope is marked as changed, indicating that while the vulnerability resides in Demand Planning, successful exploitation can impact other products in the Oracle supply chain ecosystem. A patch is likely available through Oracle's Critical Patch Update process.
Affected products
- Oracle Demand Planning 12.1, 12.2
Timeline
- 2026-08-18: disclosed