Description
Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this vulnerability can result in takeover of Oracle Sales. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Internal Operations component of Oracle Sales, part of Oracle E‑Business Suite. It allows a low‑privileged user with network access to the HTTP interface to compromise the application. The weakness is an access control flaw (CWE‑284) that enables the attacker to bypass normal controls. Successful attacks can result in takeover of Oracle Sales, giving the attacker full control over the application, including potential to read, modify, or delete data and disrupt services.

Affected Systems

Oracle Corporation’s Oracle Sales product in Oracle E‑Business Suite, supported versions 12.2.3 through 12.2.15, is impacted.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates high severity, and the vector shows remote network exploitation with low privileged interaction. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, but the risk remains because an attacker can exploit the flaw over HTTP and acquire full control of Oracle Sales. The likely attack vector is attempting unauthenticated or minimally privileged access to the HTTP endpoints of the Internal Operations component, which, if successful, would result in takeover of Oracle Sales.

Generated by OpenCVE AI on August 26, 2026 at 23:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the latest Oracle Sales patch that addresses this issue or upgrade to a supported, fixed version.
  • Restrict network access to the Oracle Sales HTTP endpoints to trusted IP ranges or implement firewall rules that block unauthorized connections.
  • If the Internal Operations component is not required, disable or isolate it to limit the attack surface.
  • Enable detailed logging and audit the logs regularly for signs of suspicious activity or exploitation attempts.

Generated by OpenCVE AI on August 26, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle e-business Suite
CPEs cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:sales:-:*:*:*:*:*:*:*
Vendors & Products Oracle e-business Suite

Thu, 27 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Access Allows Oracle Sales Compromise

Wed, 26 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote HTTP Access Enables Oracle Sales Application Takeover
Weaknesses CWE-285
CWE-287

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote HTTP Access Enables Oracle Sales Application Takeover
Weaknesses CWE-285
CWE-287

Fri, 21 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Oracle Sales Internal Operations Vulnerability Allowing Low‑Privileged Takeover via HTTP
Weaknesses CWE-284
CWE-94

Wed, 19 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Oracle Sales Internal Operations Vulnerability Allowing Low‑Privileged Takeover via HTTP
Weaknesses CWE-284
CWE-94

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this vulnerability can result in takeover of Oracle Sales. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle sales
CPEs cpe:2.3:a:oracle:sales:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle sales
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle E-business Suite Sales
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T17:34:43.887Z

Reserved: 2026-08-04T22:06:34.591Z

Link: CVE-2026-70706

cve-icon Vulnrichment

Updated: 2026-08-26T17:25:04.311Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:22.800

Modified: 2026-08-31T15:07:05.467

Link: CVE-2026-70706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:45:03Z

Weaknesses