Executive brief
Oracle Purchasing is a financial module in Oracle E-Business Suite used to manage procurement and vendor interactions. A vulnerability in this product allows a low-privileged user with network access to gain full control over the Purchasing system, compromising sensitive procurement data, transaction integrity, and system availability. This could lead to unauthorized purchases, data theft, and disruption of critical business operations.
Technical details
The vulnerability is classified as an "Other issue" (unspecified privilege escalation or authorization bypass) in the Oracle Purchasing component of Oracle E-Business Suite. It is easily exploitable via HTTP by a low-privileged authenticated user without requiring user interaction. Successful exploitation results in complete system takeover (confidentiality, integrity, and availability compromise). The vulnerability affects versions 12.2.3 through 12.2.15. Oracle has released a patch in September 2026; the specific remediation details are unavailable due to Oracle's security portal access issues.
Affected products
- Oracle E-Business Suite 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed