Executive brief
Oracle Depot Repair is a component of Oracle E-Business Suite that tracks and manages equipment repair estimates and actual charges. A flaw in this product allows low-privileged users with network access to create, delete, or modify critical repair data and access sensitive information. An attacker could tamper with repair records, pricing, and customer data, disrupting repair operations and potentially leading to financial fraud or service disruption.
Technical details
The vulnerability is an authorization flaw in the Estimate and Actual Charges component of Oracle Depot Repair (E-Business Suite 12.2.3–12.2.15) that permits low-privileged attackers to manipulate or access restricted data via HTTP. The attack requires network access and low-privilege authentication but no user interaction. Successful exploitation grants unauthorized creation, deletion, and modification of critical repair data as well as read access to all accessible data in the product. Oracle has released patches as part of its September 2026 security update cycle, with fixes available for affected versions.
Affected products
- Oracle E-Business Suite Depot Repair 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed