Executive brief
Oracle Purchasing is a critical component of Oracle's E-Business Suite, used for enterprise procurement and invoice management. A vulnerability allows low-privilege users with network access to view sensitive purchasing and invoice data without authorization, potentially exposing confidential procurement information and supplier details to unauthorized users.
Technical details
This is an unauthorized access vulnerability (CWE-639: Authorization Bypass Through User-Controlled Key) in the Oracle Purchasing product component G-Invoicing within Oracle E-Business Suite. The vulnerability is easily exploitable via HTTP network access and requires only low privileges and no user interaction to trigger. An attacker can achieve unauthorized read access to critical Purchasing data; the scope is changed meaning impacts extend to other E-Business Suite components. Affected versions are 12.2.10 through 12.2.15. A patch is expected from Oracle during their standard security update cycle.
Affected products
- Oracle E-Business Suite 12.2.10-12.2.15
Timeline
- 2026-09-15: disclosed