Description
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management. A high‑privileged attacker who can reach the application over HTTP may compromise the system and gain unauthorized access to critical data. The flaw is an Improper Access Control (CWE‑284) that lets the attacker elevate privileges to read, and potentially write, configuration and transactional data. Because the issue is in a core component, a successful exploit can also affect other Oracle E‑Business Suite products that share the same database or process environment.

Affected Systems

Oracle Order Management versions 12.2.3 through 12.2.15 are affected. The vulnerability is listed under the Oracle Corporation:Oracle Order Management product line and has no other vendor or product variants identified in the CNA data.

Risk and Exploitability

The CVSS 3.1 base score of 6.8 reflects a moderate confidentiality impact, with a remote attack vector over HTTP requiring high privileges. The EPSS score is below 1 %, indicating a low probability of exploitation in the near term, and the vulnerability is not included in CISA KEV. However, because the exploit provides a path to full data access and can alter the scope to other applications, the risk to confidential information remains significant for organizations that have not applied the patch or otherwise restricted access to the diagnostic interface.

Generated by OpenCVE AI on August 2, 2026 at 20:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Order Management security patch referenced in Oracle’s July 2026 CPU to remove the access‑control flaw.
  • Limit HTTP traffic to the Product Diagnostic Tools interface using firewall rules so that only trusted hosts can connect.
  • If the diagnostic feature is not required for operations, disable it entirely to eliminate the attack surface.

Generated by OpenCVE AI on August 2, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Access Control Exploit in Oracle Order Management Product Diagnostic Tools Allows Unauthorized Data Access

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Product Diagnostic Tools in Oracle Order Management
Weaknesses CWE-269
CWE-285

Sun, 26 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Product Diagnostic Tools in Oracle Order Management
Weaknesses CWE-269
CWE-285

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle order Management
CPEs cpe:2.3:a:oracle:order_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle order Management
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:41:29.756Z

Reserved: 2026-07-08T15:51:55.597Z

Link: CVE-2026-60862

cve-icon Vulnrichment

Updated: 2026-07-24T17:41:24.976Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:45:05Z

Weaknesses