Executive brief
Oracle Depot Repair is a component of Oracle E-Business Suite used for managing equipment repairs and recalls. A network-accessible vulnerability allows low-privileged users to bypass controls and access sensitive business data or temporarily disrupt service, potentially exposing customer information, repair records, and operational details stored in the repair system.
Technical details
This is an easily exploitable vulnerability in the Recall Management component of Oracle Depot Repair affecting versions 12.2.3 through 12.2.15. The vulnerability is reachable over HTTP and requires only low-privilege authentication; no special user interaction is needed. A successful attack results in unauthorized read access to critical data within the Depot Repair system and limited denial-of-service capability (partial DoS). The vulnerability enables confidentiality and partial availability impacts. Patches are expected to be available through Oracle's regular security update process.
Affected products
- Oracle E-Business Suite Depot Repair 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed