Description
Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales for Handhelds. Successful attacks of this vulnerability can result in takeover of Oracle Sales for Handhelds. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Internal Operations component of Oracle Sales for Handhelds, part of the Oracle E‑Business Suite. A low‑privileged attacker who can reach the application’s HTTP interface can exploit the vulnerability, allowing the attacker to fully compromise the application. Successful exploitation results in complete loss of confidentiality, integrity, and availability for the Sales for Handhelds instance, effectively granting the attacker full administrative control and the ability to leverage the system for further attacks.

Affected Systems

Oracle Corporation’s Sales for Handhelds product, versions 12.2.3 through 12.2.15, is impacted. The vulnerability is confined to the Internal Operations component within the E‑Business Suite.

Risk and Exploitability

The vulnerability has a CVSS 3.1 Base Score of 8.8, indicating high severity with high impacts to confidentiality, integrity, and availability. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, yet the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via the publicly accessible HTTP interface, requiring only low privilege, which makes the vulnerability relatively easy to exploit for an attacker with network access to the affected system.

Generated by OpenCVE AI on August 26, 2026 at 20:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s published patch or upgrade to a non‑affected version of Sales for Handhelds
  • Restrict or disable direct HTTP access to the Sales for Handhelds interface from untrusted networks
  • Enforce strict access controls and monitor privileged actions within the application

Generated by OpenCVE AI on August 26, 2026 at 20:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Exploit in Oracle Sales for Handhelds

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Exploit in Oracle Sales for Handhelds

Fri, 21 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle Sales for Handhelds via HTTP
Weaknesses CWE-284

Wed, 19 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle Sales for Handhelds via HTTP
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales for Handhelds. Successful attacks of this vulnerability can result in takeover of Oracle Sales for Handhelds. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle sales For Handhelds
CPEs cpe:2.3:a:oracle:sales_for_handhelds:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle sales For Handhelds
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Sales For Handhelds
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:24:07.316Z

Reserved: 2026-08-04T22:06:34.591Z

Link: CVE-2026-70707

cve-icon Vulnrichment

Updated: 2026-08-26T13:49:10.833Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:22.910

Modified: 2026-08-31T15:06:59.173

Link: CVE-2026-70707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:45:03Z

Weaknesses