Executive brief
Oracle Bills of Material is a component of Oracle E-Business Suite used to manage manufacturing and production data. A vulnerability allows a low-privileged user with network access to gain unauthorized access to sensitive manufacturing data, including the ability to create, modify, or delete critical records. This could result in data breaches, unauthorized changes to bill-of-materials records, and operational disruption.
Technical details
The vulnerability is an easily exploitable flaw in Oracle Bills of Material (Oracle E-Business Suite component: Internal Operations) affecting versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit this to achieve unauthorized data access and modification. The attack requires low privilege level and network reachability but no user interaction. Successful exploitation results in confidentiality and integrity impacts including unauthorized creation, deletion, or modification of critical data. A patch or update is likely available from Oracle's security advisory.
Affected products
- Oracle E-Business Suite Bills of Material 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed