Executive brief
Oracle Product Workbench is a component of Oracle E-Business Suite used for product configuration and management. This vulnerability allows a low-privileged attacker with network access to trick authorized users into unknowingly modifying or viewing sensitive product data through a malicious webpage, compromising the confidentiality and integrity of business-critical product information.
Technical details
This is a cross-site request forgery (CSRF) or similar UI-based vulnerability in the WebUI component of Oracle Product Workbench affecting versions 12.2.3 through 12.2.15. The vulnerability requires low-level privileges and network access via HTTP, but critically depends on user interaction (phishing or social engineering) to succeed. A successful attack results in unauthorized read, update, insert, or delete operations on accessible data within Product Workbench, and may have cascading impacts on other Oracle E-Business Suite products due to scope change. Patch availability has not been confirmed at the time of this advisory.
Affected products
- Oracle Product Workbench 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed