Executive brief
Oracle E-Business Suite's Product Workbench is a component used to manage product data and operations in enterprise resource planning systems. This vulnerability allows a low-privileged attacker with network access to bypass authorization controls and read or modify critical business data, potentially compromising product records, pricing, configurations, and operational integrity across the entire system.
Technical details
This is a privilege escalation vulnerability in the Internal Operations component of Oracle Product Workbench. The vulnerability is easily exploitable by a low-privileged attacker over the network via HTTP, requiring no additional user interaction. An attacker with valid credentials can gain unauthorized read and write access to critical and sensitive data within the Product Workbench application. The attack vector is network-based with low complexity and low privilege requirements. Patched versions are expected to be available from Oracle.
Affected products
- Oracle E-Business Suite 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed