Executive brief
Oracle Bills of Material is a module within Oracle E-Business Suite used to manage product structures and manufacturing operations. This vulnerability allows a low-privileged user with network access to gain unauthorized access to sensitive manufacturing and operational data, or disrupt service availability. The issue can also impact other E-Business Suite components beyond the Bills of Material module itself.
Technical details
This is a network-accessible vulnerability in the Oracle Bills of Material component of E-Business Suite (versions 12.2.3 through 12.2.15) within the Internal Operations module. The vulnerability requires low-level privilege (authenticated user) and HTTP network access, but no user interaction. Successful exploitation grants attackers unauthorized access to critical business data accessible by Bills of Material and the ability to cause partial denial of service. The scope is marked as changed, indicating impacts beyond the vulnerable component itself. A patch or mitigation is expected from Oracle's September 2026 security update cycle.
Affected products
- Oracle E-Business Suite Bills of Material 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed