Executive brief
Oracle E-Business Suite's Purchasing module is a core financial application used to manage purchase orders, vendor relationships, and procurement workflows. A vulnerability in this component allows low-privileged users with network access to view, create, modify, or delete sensitive procurement data and financial records that should be restricted. Exploitation could lead to unauthorized financial transactions, data theft, or system compromise.
Technical details
The vulnerability is an insufficient access control issue in the Oracle E-Business Suite Purchasing product (versions 12.2.3–12.2.15). It is exploitable by low-privileged, authenticated attackers over the network via HTTP without user interaction required. The vulnerability allows unauthorized creation, deletion, and modification of critical purchasing data, as well as unauthorized access to sensitive financial information. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) indicates network accessibility, low attack complexity, and high impact to confidentiality and integrity. Patch status and details are not publicly available at this time.
Affected products
- Oracle E-Business Suite Purchasing 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed