Executive brief
Oracle One-to-One Fulfillment is a component of Oracle E-Business Suite used for managing customer order fulfillment and related operations. An unauthenticated attacker with network access can exploit a difficult-to-exploit Java Server vulnerability via HTTP to gain complete control of the system, compromising confidentiality, integrity, and availability of customer and operational data.
Technical details
A difficult-to-exploit remote code execution vulnerability exists in the Java Server component of Oracle One-to-One Fulfillment (part of Oracle E-Business Suite versions 12.2.3–12.2.15). The vulnerability is reachable via HTTP from the network without authentication or user interaction. Successful exploitation allows an attacker to achieve complete system compromise, including unauthorized access to data and the ability to modify or deny service. The high complexity attack complexity (AC:H) suggests specific conditions or detailed exploitation knowledge is required, but the CVSS 8.1 score reflects the severity of impact once compromised.
Affected products
- Oracle E-Business Suite One-to-One Fulfillment 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed