Executive brief
Oracle Demand Signal Repository is a component of Oracle E-Business Suite used for managing supply chain and demand forecasting data. A low-privileged network attacker can exploit this vulnerability to create, delete, or modify critical business data without authorization, or crash the application repeatedly, causing operational disruption.
Technical details
This is a privilege escalation vulnerability in Oracle Demand Signal Repository (versions 12.2.3–12.2.15) affecting the Internal Operations component. The vulnerability allows a low-privileged attacker with network access via HTTP to bypass authorization controls and execute unauthorized operations. An attacker can create, delete, or modify data in the repository and trigger denial-of-service conditions through repeated crashes. The vulnerability requires network reachability and valid low-privilege credentials but does not require special user interaction. No patched version information is currently available.
Affected products
- Oracle E-Business Suite Demand Signal Repository 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed