Description
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Order Management accessible data as well as unauthorized read access to a subset of Oracle Order Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Order Management’s Product Diagnostic Tools enables a low‑privileged attacker with HTTP network access to modify, delete, or read restricted data. By exploiting this flaw, an attacker can perform unauthorized updates, insertions, or deletions and gain read access to sensitive Oracle Order Management data without passing authentication or authorization checks, thereby compromising data integrity and confidentiality.

Affected Systems

Affected are Oracle Order Management versions 12.2.3 through 12.2.15 as part of Oracle E‑Business Suite. Deployments that expose the Product Diagnostic Tools component over HTTP are susceptible, and the flaw may indirectly affect additional related products due to a scope change.

Risk and Exploitability

The CVSS 3.1 base score of 6.4 indicates moderate risk, while the EPSS score of less than 1 % points to a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the scope expansion to other products increases potential impact. Successful exploitation requires an attacker with low‑level network access to the Product Diagnostic Tools via HTTP, allowing them to read, insert, update or delete data without proper authorization, thereby compromising data integrity and confidentiality.

Generated by OpenCVE AI on August 5, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Order Management patch or upgrade to a version newer than 12.2.15.
  • Restrict HTTP access to the Product Diagnostic Tools by limiting exposure to trusted hosts via firewall or network segmentation.
  • Review and tighten low‑privilege user permissions in Oracle Order Management to ensure minimal rights for accounts that could exploit the flaw.

Generated by OpenCVE AI on August 5, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Product Diagnostic Tools in Oracle Order Management
Weaknesses CWE-284
CWE-285

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Data Modification and Disclosure in Oracle Order Management
Weaknesses CWE-284

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Data Modification and Disclosure in Oracle Order Management
Weaknesses CWE-284

Mon, 27 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Exploit in Oracle Order Management Allowing Unauthorized Data Access
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Exploit in Oracle Order Management Allowing Unauthorized Data Access
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Order Management accessible data as well as unauthorized read access to a subset of Oracle Order Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle order Management
CPEs cpe:2.3:a:oracle:order_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle order Management
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:52:09.638Z

Reserved: 2026-07-08T15:51:55.597Z

Link: CVE-2026-60864

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses