Executive brief
A vulnerability in Oracle Spares Management, a component of Oracle E-Business Suite used for managing spare parts inventory, allows a low-privileged network attacker to gain full control over the application. Successful exploitation can lead to complete takeover of the Spares Management system, compromising all confidential data, ability to modify records, and overall system availability.
Technical details
This is an easily exploitable privilege escalation vulnerability in the Internal Operations component of Oracle Spares Management that requires only low-privilege network access via HTTP. The vulnerability allows an authenticated attacker with low privileges to escalate access and compromise the entire system (confidentiality, integrity, and availability impacts). Attack vector is network-based with low attack complexity and no user interaction required. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Patch status and detailed remediation guidance should be available from Oracle's security advisories.
Affected products
- Oracle E-Business Suite Spares Management 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed