Description
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability resides in the Product Diagnostic Tools component of Oracle Order Management for Oracle E‑Business Suite versions 12.2.3 through 12.2.15. An attacker with low privileges who can reach the system over HTTP can exploit the flaw, gaining unauthorized access to critical data or full access to all data that Oracle Order Management can expose. The known CVSS v3.1 Base Score of 6.5 reflects the impact on confidentiality, while integrity and availability remain unaffected.

Affected Systems

Oracle Corporation’s Oracle Order Management product, part of the Oracle E‑Business Suite, is affected. The vulnerability applies to all released sub‑versions in the 12.2.3–12.2.15 release line. Administrators should verify that their deployed instances fall within this range and are not patched.

Risk and Exploitability

CVSS 6.5 places the vulnerability in the moderate severity category. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack likely requires only network access to the HTTP interface and does not need elevated privileges beyond a low‑privileged user, making it relatively easy to exploit for an attacker who can reach the exposed endpoint.

Generated by OpenCVE AI on August 4, 2026 at 01:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Critical Patch Update that addresses this flaw for all affected 12.2.3–12.2.15 versions
  • Restrict network access to the Product Diagnostic Tools endpoints by firewall rules or web application firewall settings so only trusted administrators can reach them
  • Monitor HTTP traffic and application logs for anomalies related to the diagnostic tools and enforce strict access control for users that can invoke these interfaces

Generated by OpenCVE AI on August 4, 2026 at 01:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability in Oracle Order Management Enables Unauthorized Data Access

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability in Oracle Order Management Enables Unauthorized Data Access

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Remote unauthorized data access via low privilege HTTP in Oracle Order Management

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote unauthorized data access via low privilege HTTP in Oracle Order Management
Weaknesses CWE-200
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle order Management
CPEs cpe:2.3:a:oracle:order_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle order Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:37:19.649Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61112

cve-icon Vulnrichment

Updated: 2026-07-23T19:37:15.359Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control