Executive brief
Oracle Purchasing is a component of Oracle E-Business Suite used to manage procurement and invoicing operations. A vulnerability in the G-Invoicing module allows low-privileged attackers with network access to unauthorized create, delete, or modify critical purchasing data, as well as read sensitive information. This can result in financial fraud, data theft, and operational disruption for organizations using this system.
Technical details
A vulnerability exists in the Oracle Purchasing product (G-Invoicing component) of Oracle E-Business Suite affecting versions 12.2.11 through 12.2.15. The vulnerability is easily exploitable via HTTP and requires only low-privilege authentication and network access (no additional user interaction needed). An authenticated attacker can achieve both confidentiality and integrity impacts, including unauthorized creation, deletion, or modification of critical purchasing data, and unauthorized access to all Oracle Purchasing data. The vulnerability has been assigned CVSS 3.1 score of 8.1. Patch availability should be confirmed through Oracle's security updates.
Affected products
- Oracle E-Business Suite 12.2.11-12.2.15
Timeline
- 2026-09-15: disclosed