Executive brief
A data exposure vulnerability in Oracle E-Business Suite's Product Hub component allows low-privileged attackers with network access to view sensitive catalog and product data. An attacker could exploit this flaw to gain unauthorized access to critical business information stored in the Item Catalog without requiring admin privileges or user interaction. The vulnerability affects versions 12.2.3 through 12.2.15 and could compromise additional Oracle systems beyond the Product Hub itself.
Technical details
This is an information disclosure vulnerability in the Oracle E-Business Suite Product Hub's Item Catalog component, reachable via HTTP. The vulnerability requires low privilege authentication and can be exploited remotely without user interaction. It allows attackers to access confidential data within Oracle Product Hub; the scope classification (S:C) indicates that compromise of the vulnerable component may significantly impact other connected products or systems. No user interaction is required. Patches are expected as part of Oracle's security updates; consult Oracle's official security advisories for patch availability.
Affected products
- Oracle E-Business Suite 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed