Description
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data exposure
Action: Patch Immediately
AI Analysis

Impact

A flaw in Oracle Bills of Material’s Setup Workbench enables a low‑privileged attacker with network access via HTTP to gain unauthorized access to critical data. The vulnerability, rated CVSS 7.7, is easily exploitable and can lead to full access to all database objects exposed by the product. The weakness corresponds to improper access control and improper privilege management, leaving confidentiality severely impacted while integrity and availability remain largely unaffected.

Affected Systems

Oracle Bills of Material, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The vulnerability operates in the Setup Workbench component and may also influence other Oracle products that rely on the same data layer.

Risk and Exploitability

The CVSS 7.7 score indicates high severity, but the EPSS score of less than 1% shows that the likelihood of exploitation in the wild is currently low. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it remotely without authentication but require low‑privilege access, making the attack vector network‑based HTTP. Successful exploitation can lead to confidential data leakage or complete loss of control over Bills of Material data.

Generated by OpenCVE AI on September 20, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Oracle Bills of Material to the latest patched release that addresses the vulnerability
  • Restrict external HTTP access to the Setup Workbench interface, preferably by firewalls or network segmentation
  • Monitor logs for suspicious access patterns to the Setup Workbench and other E‑Business Suite components

Generated by OpenCVE AI on September 20, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure via Low-Privilege HTTP Access in Oracle Bills of Material

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Attack Compromise Oracle Bills of Material
Weaknesses CWE-284
CWE-285

Wed, 16 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Attack Compromise Oracle Bills of Material
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle bills Of Material
CPEs cpe:2.3:a:oracle:bills_of_material:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bills Of Material
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Bills Of Material
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:15:53.112Z

Reserved: 2026-09-08T21:49:12.398Z

Link: CVE-2026-87151

cve-icon Vulnrichment

Updated: 2026-09-18T18:15:48.227Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:02.547

Modified: 2026-09-18T19:17:10.230

Link: CVE-2026-87151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:30:16Z

Weaknesses