Executive brief
Oracle Demand Signal Repository is a supply chain planning component within Oracle E-Business Suite that manages demand forecasting and inventory data. A low-privileged network attacker can exploit an easily exploitable vulnerability in versions 12.2.3-12.2.15 to read, modify, or delete critical business data, potentially compromising supply chain visibility and decision-making.
Technical details
The vulnerability in Oracle Demand Signal Repository (component: Internal Operations) is easily exploitable by a low-privileged attacker over the network via HTTP, requiring only valid user credentials (PR:L) and no user interaction. The vulnerability allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all accessible repository data. The root cause and specific vulnerable component are not detailed in available public references. Affected versions are 12.2.3 through 12.2.15 of Oracle E-Business Suite. Oracle has released fixes as part of their security updates; patched versions should be applied immediately.
Affected products
- Oracle E-Business Suite Demand Signal Repository 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed