Description
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Order Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Product Diagnostic Tools component of Oracle Order Management within Oracle E-Business Suite. An attacker who can reach the application via HTTP and only requires a low-privileged account may trigger missing authorization checks to read all Order Management data and perform unauthorized insert, update or delete operations. The flaw results in high confidentiality loss and lower but still significant integrity impact, allowing an attacker to modify or delete records they normally could not access.

Affected Systems

Affected are Oracle Order Management installations running versions 12.2.3 through 12.2.15, part of Oracle E-Business Suite. The product is exposed to normal HTTP traffic, and the vulnerability can be exploited by any user with network connectivity to that service. Although the flaw is confined to Order Management, the scope change noted in the CVSS vector means that compromising this component could also affect other integrated Oracle products.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 classifies the issue as high severity. EPSS of 0.00242 indicates a very low yet non-zero probability of exploitation in the near term. The vulnerability is not listed in CISA KEV. Attackers can act externally over the network (AV:N), with high complexity but only low privilege (PR:L) and no user interaction required. The likely attack vector is a HTTP request to a diagnostic endpoint, making the flaw remote in nature and potentially exploitable by relatively unsophisticated threat actors.

Generated by OpenCVE AI on August 21, 2026 at 08:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Order Management patch or upgrade to a version newer than 12.2.15.
  • Limit HTTP access to the Order Management interface to trusted IP addresses or enforce VPN access to reduce exposure to low-privileged attackers.
  • Disable the Product Diagnostic Tools feature for users lacking appropriate permissions or restrict its use to privileged accounts.

Generated by OpenCVE AI on August 21, 2026 at 08:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Missing Authorization in Oracle Order Management
Weaknesses CWE-284
CWE-862

Fri, 21 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Exploitation in Oracle Order Management Enables Data Compromise
Weaknesses CWE-284
CWE-862

Wed, 19 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Exploitation in Oracle Order Management Enables Data Compromise
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Order Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle order Management
CPEs cpe:2.3:a:oracle:order_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle order Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T19:54:23.867Z

Reserved: 2026-08-04T22:06:34.595Z

Link: CVE-2026-70760

cve-icon Vulnrichment

Updated: 2026-08-24T19:50:28.290Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:28.593

Modified: 2026-08-28T18:26:37.407

Link: CVE-2026-70760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:45:12Z

Weaknesses