Executive brief
Oracle E-Business Suite's One-to-One Fulfillment module handles order fulfillment and customer document management for enterprise customers. A vulnerability in the Documents component allows low-privileged users with network access to gain unauthorized read, create, modify, or delete access to sensitive fulfillment data. This could expose customer orders, payment information, and other critical business data, or enable attackers to disrupt order processing operations.
Technical details
A vulnerability in the Documents component of Oracle E-Business Suite's One-to-One Fulfillment module allows low-privileged authenticated users to access, modify, or delete data they should not be authorized to. The vulnerability is exploitable via HTTP with low complexity, requiring only valid user credentials (network-based, no additional user interaction needed). Successful exploitation enables unauthorized access to all One-to-One Fulfillment data including critical customer and order information, as well as creation or modification of documents. Affected versions include 12.2.3 through 12.2.15; patches are expected from Oracle's critical patch update cycle.
Affected products
- Oracle E-Business Suite One-to-One Fulfillment 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed