Executive brief
Oracle Bills of Material is a component of Oracle E-Business Suite used to manage product manufacturing and inventory structures. A network-accessible vulnerability allows low-privileged users to gain unauthorized access to modify, create, or delete critical manufacturing data, potentially disrupting production operations and exposing sensitive business information across interconnected systems.
Technical details
This vulnerability in Oracle Bills of Material (component: Internal Operations) is a scope-changing flaw affecting versions 12.2.13 through 12.2.15. It requires low privilege credentials and network access via HTTP to exploit, but does not require user interaction. An authenticated attacker can compromise data confidentiality and integrity within Bills of Material and potentially escalate impact to other E-Business Suite modules. The vulnerability is rated difficult to exploit due to access control hurdles (AC:H), but carries high impact once successful. Patches are available from Oracle.
Affected products
- Oracle E-Business Suite Bills of Material 12.2.13-12.2.15
Timeline
- 2026-09-15: disclosed