Executive brief
Oracle Product Hub is a data management component within Oracle's E-Business Suite, used to manage product information and related business operations. A vulnerability allows low-privileged network attackers to gain unauthorized access to sensitive product data and modify or delete records, potentially exposing critical business information or causing data integrity issues.
Technical details
An easily exploitable vulnerability in the Oracle Product Hub component (Internal Operations) allows an attacker with low privileges and network access via HTTP to bypass authorization controls. The vulnerability affects versions 12.2.3 through 12.2.15 of Oracle E-Business Suite. Successful exploitation results in unauthorized read access to all accessible Product Hub data and the ability to perform unauthorized insert, update, or delete operations on some data. No user interaction or additional credentials beyond basic network access are required for exploitation. A patch is expected to be available through Oracle's security advisory program.
Affected products
- Oracle E-Business Suite 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed