ZeroHour

CVE-2026-87151

moderate

Authenticated Information Disclosure in Oracle EBS Bills of Material (Setup Workbench)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87151 is a high-severity information disclosure vulnerability in the Setup Workbench component of Oracle Bills of Material, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP — for example, any authenticated EBS user with minimal permissions — can exploit the flaw without user interaction to read data beyond their normal authorization boundary. Because of a scope change, successful attacks not only expose Oracle Bills of Material data but can significantly impact additional E-Business Suite products, potentially yielding unauthorized access to critical business data or complete access to all data reachable through the Bills of Material module. The flaw carries a CVSS 3.1 base score of 7.7, driven entirely by high confidentiality impact. No public proof of concept exists and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no indication of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediates this vulnerability to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances reachable over HTTP. Restrict EBS web endpoints to VPN or trusted networks so that low-privileged accounts cannot reach the Setup Workbench from the open internet. Review audit logs for anomalous data-access patterns by low-privilege users against Bills of Material / Setup Workbench functions, and check whether other EBS modules' data was accessed in a scope-change scenario.

Affected
Oracle E-Business Suite (Oracle Bills of Material, Setup Workbench component)12.2.3 - 12.2.15
Estimated exposure
moderate≈ thousands of internet-exposed EBS instances out of an estimated tens of thousands of on-premises deployments worldwide (clearly an estimate) — Oracle E-Business Suite is on-premises enterprise software with tens of thousands of organizational deployments, and public internet scans (e.g., Shodan-type surveys) have historically shown a few thousand EBS login pages exposed directly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.