Impact
An easily exploitable vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management. Successful exploitation allows a low‑privileged attacker with network access over HTTP to compromise the entire Order Management instance, resulting in full control of the application and the data it handles. The impact is severe, affecting confidentiality, integrity, and availability. The described weakness aligns with improper access control and inappropriate privilege assignment.
Affected Systems
Oracle Corporation’s Oracle Order Management product is affected. The vulnerability applies to supported versions ranging from 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity, with an attack vector of network (HTTP) and low privilege requirements. The EPSS score of less than 1% suggests a very low current exploitation probability, but the vulnerability is listed as not currently in CISA’s KEV catalog. A low‑privileged attacker with network access over HTTP can exploit the flaw, and the vulnerability impacts the entire application rather than a single user or session.
OpenCVE Enrichment