Executive brief
Oracle E-Business Suite's Installed Base module, which tracks fixed assets and equipment across an organization, contains a vulnerability in the Create Item Instance component that allows attackers with low-level database access to bypass authorization controls. A successful exploitation could permit unauthorized viewing, modification, or deletion of critical asset data, compromising the accuracy of financial records and asset management operations.
Technical details
The vulnerability is an authorization bypass in the Create Item Instance component of Oracle E-Business Suite's Installed Base module, affecting versions 12.2.3 through 12.2.15. The flaw is easily exploitable and requires network access via HTTP and a low-privilege user account; no additional user interaction is necessary. An attacker can achieve unauthorized creation, modification, or deletion of asset data, as well as read access to sensitive Installed Base information. The CVSS 3.1 vector indicates high confidentiality and integrity impact with low complexity and no scope escalation. Patch availability is expected via Oracle's Critical Patch Update process, typically released on published quarterly security update schedules.
Affected products
- Oracle E-Business Suite 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed