Description
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. While the vulnerability is in Oracle Purchasing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Immediately
AI Analysis

Impact

A flaw in the G‑Invoicing module of Oracle Purchasing allows a low‑privilege user with network access over HTTP to bypass normal access controls and read data that should be restricted. The vulnerability can result in exposure of all purchasing‑related information accessible through the application, directly compromising the confidentiality of the system’s data.

Affected Systems

Oracle Purchasing versions 12.2.10 through 12.2.15 are affected. Attacks may extend beyond the Purchasing module because the vulnerability changes the scope of protected resources, potentially impacting other components of the Oracle E‑Business Suite that share data with Purchasing.

Risk and Exploitability

The CVSS v3.1 base score of 7.7 reflects a high‑severity confidentiality impact. The EPSS score is less than 1%, indicating a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers only need low privilege and the ability to reach the application over HTTP, which makes the attack vector feasible for remote actors with minimal access. If exploited, the attacker could gain unauthorized read access to all data the application can provide, and the scope change raises the danger of affecting other Oracle products that share the same data store.

Generated by OpenCVE AI on September 22, 2026 at 00:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle Purchasing security patch that addresses the G‑Invoicing flaw for the vulnerable 12.2.10‑12.2.15 releases.
  • Limit HTTP access to the Purchasing endpoint by whitelisting internal addresses or enforcing VPN connectivity.
  • Review and tighten role‑based access controls to ensure users with low privileges cannot retrieve data beyond their authorized scope.

Generated by OpenCVE AI on September 22, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Oracle Purchasing G‑Invoicing Unauthorized Data Access via HTTP
Weaknesses CWE-285
CWE-639

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Oracle Purchasing G‑Invoicing Unauthorized Data Access via HTTP
Weaknesses CWE-285
CWE-639

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-privileged HTTP Exploit in Oracle Purchasing Allows Unauthorized Data Access
Weaknesses CWE-284
CWE-287

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Low-privileged HTTP Exploit in Oracle Purchasing Allows Unauthorized Data Access
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. While the vulnerability is in Oracle Purchasing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle purchasing
CPEs cpe:2.3:a:oracle:purchasing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle purchasing
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Purchasing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:23:12.333Z

Reserved: 2026-09-08T21:49:12.396Z

Link: CVE-2026-87127

cve-icon Vulnrichment

Updated: 2026-09-21T19:23:08.784Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:59.713

Modified: 2026-09-22T19:05:23.900

Link: CVE-2026-87127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T00:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor