Description
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management within Oracle E‑Business Suite. A high‑privileged attacker who can reach the application over HTTP can exploit the flaw, leading to a full takeover of the Order Management subsystem. Successful exploitation compromises confidentiality, integrity, and availability, effectively allowing an attacker to control the entire Order Management system.

Affected Systems

Oracle Corporation’s Oracle Order Management product is affected. All supported releases from version 12.2.3 through 12.2.15 of the Oracle E‑Business Suite are vulnerable and remain susceptible until a fix is applied.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 indicates high severity, and the EPSS score of less than 1% suggests a low current exploitation probability. The flaw is network‑accessible over HTTP, requiring only high‑privileged credentials, and is not yet listed in the CISA KEV catalog. Despite the low EPSS, the potential for full system compromise warrants proactive remediation.

Generated by OpenCVE AI on August 4, 2026 at 16:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the Oracle security patch for Order Management (12.2.3–12.2.15) that fixes the Product Diagnostic Tools vulnerability.
  • Restrict HTTP access to the Order Management application to trusted networks or enforce IP‑based firewall rules to limit exposure to privileged users.
  • If the Product Diagnostic Tools feature is not needed, disable or remove it entirely to reduce the attack surface.
  • Monitor logs and audit activity for suspicious exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Takeover via HTTP in Oracle Order Management Product Diagnostic Tools

Sun, 02 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Takeover via HTTP in Oracle Order Management Product Diagnostic Tools

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Code Execution via HTTP in Oracle Order Management

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Code Execution via HTTP in Oracle Order Management

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle order Management
CPEs cpe:2.3:a:oracle:order_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle order Management
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:38:44.708Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61115

cve-icon Vulnrichment

Updated: 2026-07-23T19:38:40.576Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses