Executive brief
Oracle Spares Management is a module within Oracle E-Business Suite used to manage spare parts inventory and operations. A vulnerability in this component allows a low-privileged user with network access to gain complete control over the Spares Management system, potentially compromising confidential data, modifying critical inventory information, and disrupting supply chain operations.
Technical details
The vulnerability is an easily exploitable flaw in the Oracle Spares Management component (Internal Operations) of E-Business Suite that affects versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit this issue without user interaction to achieve authentication bypass or privilege escalation. Successful exploitation results in complete compromise of the affected Spares Management instance, leading to unauthorized access to sensitive data, integrity violations, and potential denial of service. The CVSS 3.1 score of 8.8 reflects the high impact on confidentiality, integrity, and availability. No patch status is explicitly confirmed in the advisory.
Affected products
- Oracle E-Business Suite Spares Management 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed