Executive brief
Oracle Engineering is a critical component of Oracle E-Business Suite used to manage engineering projects and changes. A vulnerability in the Change Management module allows a low-privileged user with network access to gain unauthorized access to sensitive engineering data. While contained to the Engineering product, successful exploitation could impact other connected Oracle systems and expose confidential project information.
Technical details
The vulnerability is an easily exploitable flaw in the Change Management component of Oracle Engineering (Oracle E-Business Suite) that requires low privilege credentials and network access via HTTP. The vulnerability allows attackers to bypass authorization controls and access data they should not have permission to view. The attack is unauthenticated at the network level but requires an existing low-privilege account; no user interaction is needed. Successful exploitation results in unauthorized access to critical Engineering data, with potential scope change affecting other Oracle E-Business Suite products. CVSS 3.1 score of 7.7 reflects high confidentiality impact with no integrity or availability impact.
Affected products
- Oracle E-Business Suite 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed