Executive brief
Oracle Product Hub is a component within Oracle E-Business Suite that manages product information and operations. A network-accessible vulnerability allows authenticated users with low privileges to read, modify, or delete critical business data without proper authorization, potentially exposing sensitive product and operational information across the entire system.
Technical details
The vulnerability in Oracle Product Hub's Internal Operations component is easily exploitable and affects versions 12.2.3 through 12.2.15. It requires network access via HTTP and low-privilege user credentials, but no user interaction. A successful attack grants unauthorized read and write access to critical data stored within the Product Hub application, compromising both confidentiality and integrity. The CVSS 3.1 score of 8.1 reflects high-impact data access and modification capabilities with no availability impact. Patches are expected from Oracle's security update cycle.
Affected products
- Oracle E-Business Suite 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed