Executive brief
Oracle E-Business Suite Workflow handles email notifications and critical business process communications. A low-privileged network attacker can exploit this vulnerability to modify or delete sensitive business data, or crash the entire Workflow system causing operational disruption. This affects organizations relying on Workflow for order management, approvals, and compliance auditing.
Technical details
This is an integrity and availability vulnerability in the Workflow Notification Mailer component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable via HTTP by a low-privileged authenticated attacker with network access. Successful exploitation allows unauthorized creation, deletion, or modification of critical data within Oracle Workflow, or the ability to cause repeated denial-of-service conditions (hangs or crashes). The attack requires network connectivity and valid credentials but no user interaction. Patches are expected from Oracle's Critical Patch Update program.
Affected products
- Oracle E-Business Suite Workflow 12.2.3 to 12.2.15
Timeline
- 2026-08-18: disclosed