Executive brief
Oracle Demand Signal Repository is a supply chain planning component within Oracle E-Business Suite used to manage inventory and demand forecasting. An authenticated attacker with network access can exploit a vulnerability to gain unauthorized read, create, delete, or modification access to critical data within the repository. This could allow an attacker to corrupt or exfiltrate sensitive supply chain and demand data, compromising business continuity and decision-making.
Technical details
The vulnerability in Oracle Demand Signal Repository (component: Internal Operations) is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the system. The attack requires authentication (low privilege credentials) and network reachability but no user interaction. Successful exploitation results in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all accessible data within the repository. The CVSS 3.1 score of 8.1 reflects high confidentiality and integrity impacts with no availability impact. Oracle has published patches for affected versions 12.2.3 through 12.2.15.
Affected products
- Oracle E-Business Suite Demand Signal Repository 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed