Executive brief
A vulnerability in Oracle's Purchasing module (part of E-Business Suite) allows low-privileged users to gain unauthorized access to purchase order and invoicing data, as well as create, modify, or delete critical procurement records. An attacker with network access and basic system credentials can compromise data confidentiality and integrity without needing elevated privileges.
Technical details
A vulnerability in the G-Invoicing component of Oracle's Purchasing module allows low-privileged attackers with network access via HTTP to bypass authorization controls. The vulnerability requires low privileges and no user interaction, making it easily exploitable by authenticated users. Successful exploitation enables unauthorized creation, deletion, and modification of critical procurement data, as well as read access to sensitive purchasing records. The issue affects Oracle E-Business Suite versions 12.2.10 through 12.2.15; patch availability and remediation details should be confirmed through Oracle's official security advisories.
Affected products
- Oracle E-Business Suite Purchasing 12.2.10 through 12.2.15
Timeline
- 2026-09-15: disclosed