Description
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Bills of Material allows a low‑privileged network attacker with HTTP access to compromise confidentiality, integrity, and availability of the module, potentially enabling full takeover of the application. The flaw can impact additional Oracle E‑Business Suite components due to a scope change, allowing compromised credentials or execution paths to threaten adjoining systems.

Affected Systems

Oracle Bills of Material, a component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS Base Score of 8.5 indicates high severity. Exploitation requires only HTTP network access and an account with low privileges. The EPSS score is less than 1%, and the issue is not listed in CISA KEV. The likely attack vector is network traffic over HTTP to the Bills of Material endpoints, and the flaw’s scope may also affect other E‑Business Suite products.

Generated by OpenCVE AI on August 21, 2026 at 10:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle patch for Bills of Material versions 12.2.3 through 12.2.15 as specified in the Oracle security advisory.
  • Restrict HTTP access to the Bills of Material application by limiting it to trusted IP ranges or network segments, and ensure that those segments are properly firewall‑protected.
  • Enforce strict least privilege for all users logging into Bills of Material, and review role permissions to ensure that low‑privileged accounts cannot perform actions that would enable control of the system.
  • Monitor application and web‑server logs for unusual authentication or transaction patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on August 21, 2026 at 10:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Takeover of Oracle Bills of Material
Weaknesses CWE-284

Fri, 21 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Allows Complete Takeover of Oracle Bills of Material
Weaknesses CWE-284

Wed, 19 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Allows Complete Takeover of Oracle Bills of Material
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bills Of Material
CPEs cpe:2.3:a:oracle:bills_of_material:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bills Of Material
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Bills Of Material
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:11:55.332Z

Reserved: 2026-08-04T22:06:34.592Z

Link: CVE-2026-70718

cve-icon Vulnrichment

Updated: 2026-08-25T15:06:16.767Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:24.207

Modified: 2026-08-31T15:06:02.767

Link: CVE-2026-70718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T10:15:13Z

Weaknesses