Description
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Bill Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Bill Issues component of Oracle Bills of Material, an inappropriate access control weakness (CWE‑284), allows an attacker who can execute low‑privilege operations over the network via HTTP to take full control of the application. The vulnerability is classified with CVSS 3.1 score 8.8 and vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating complete compromise of confidentiality, integrity and availability.

Affected Systems

Oracle Bills of Material, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The product is provided by Oracle Corporation.

Risk and Exploitability

The EPSS score is reported as < 1 %, showing that actual exploitation is currently considered unlikely, and the vulnerability is not in the CISA KEV catalog. Nevertheless, since the attack requires only network access over HTTP, a low‑privilege attacker could walk the path to compromise if the service is reachable from outside the trusted network. The high CVSS score reflects its severe impact once exploited.

Generated by OpenCVE AI on August 4, 2026 at 17:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Oracle Bills of Material
  • Restrict inbound HTTP traffic to Oracle Bills of Material servers using firewall rules or access control lists
  • Limit the public exposure of the Bill Issues component by placing it behind a VPN or internal network boundary

Generated by OpenCVE AI on August 4, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Oracle Bills of Material Remote Code Execution via HTTP

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Oracle Bills of Material Remote Code Execution via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Bill Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bills Of Material
CPEs cpe:2.3:a:oracle:bills_of_material:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bills Of Material
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Bills Of Material
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:07:26.141Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47031

cve-icon Vulnrichment

Updated: 2026-07-23T16:16:04.479Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses