Description
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Modification
Action: Apply Vendor Patch
AI Analysis

Impact

A vulnerability exists in Oracle Purchasing’s G‑Invoicing component that allows an attacker with limited local privileges and network access via HTTP to create, delete, or modify critical data. Successful exploitation leads to unauthorized manipulation of all accessible Oracle Purchasing data, impacting confidentiality and integrity as reflected by the CVSS score of 8.1. The weakness is a form of improper access control, allowing attackers to bypass defined data protection mechanisms.

Affected Systems

Oracle Corporation’s Oracle Purchasing product for E‑Business Suite, specifically versions 12.2.11 through 12.2.15, is susceptible to this flaw.

Risk and Exploitability

The CVSS indicates significant risk with high confidentiality and integrity impact, while the EPSS score of fewer than 1% suggests low exploitation probability at this time. The vulnerability is not catalogued in CISA’s KEV. The likely attack vector involves remote network activity over HTTP, requiring only low privileges to compromise Oracle Purchasing. An attacker could leverage this to gain full access to or alter corporate data within the application without affecting availability.

Generated by OpenCVE AI on September 21, 2026 at 03:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle Purchasing patch that addresses the G‑Invoicing vulnerability.
  • Restrict HTTP access to Oracle Purchasing to trusted IPs only.
  • Implement application monitoring for unauthorized data changes.

Generated by OpenCVE AI on September 21, 2026 at 03:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Purchasing via G‑Invoicing Access Control Flaw
Weaknesses CWE-285

Mon, 21 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Purchasing via G‑Invoicing Access Control Flaw
Weaknesses CWE-285

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑privileged Attackers Can Modify Critical Data in Oracle Purchasing
Weaknesses CWE-284

Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Low‑privileged Attackers Can Modify Critical Data in Oracle Purchasing
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle purchasing
CPEs cpe:2.3:a:oracle:purchasing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle purchasing
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Purchasing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-20T23:53:13.380Z

Reserved: 2026-09-08T21:49:12.400Z

Link: CVE-2026-87167

cve-icon Vulnrichment

Updated: 2026-09-20T23:45:32.541Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:04.390

Modified: 2026-09-22T19:02:12.997

Link: CVE-2026-87167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:45:08Z

Weaknesses