Description
Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Warehouse Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Warehouse Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-70774 describes a flaw in Oracle Warehouse Management that permits attackers with low privileges and network connectivity over HTTP to create, delete or alter data and trigger a partial denial of service. The weakness is an improper authorization control, allowing unauthorized use of privileged functions. This leads to loss of data integrity and limited availability disruption for the Warehouse Management application.

Affected Systems

Affected are Oracle Warehouse Management versions 12.2.3 through 12.2.15, as part of Oracle E‑Business Suite’s Internal Operations component. The vulnerability exists in all supported releases within that range.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 indicates a moderate to high severity, with integral and availability impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires low privilege and remote network access via HTTP, making it relatively easy to exploit from any host that can reach the application. Once exploited, an attacker can change critical data and cause a partial denial of service.

Generated by OpenCVE AI on August 21, 2026 at 05:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch or update for Warehouse Management versions 12.2.3 to 12.2.15.
  • Restrict HTTP access to the Warehouse Management instance to trusted networks or VPN connections to reduce the attack surface.
  • Enable and regularly review application audit logs to detect and respond to unauthorized create, delete, or modify actions.

Generated by OpenCVE AI on August 21, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low-Privilege HTTP Exploit

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low-Privilege HTTP Exploit
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Warehouse Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Warehouse Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle warehouse Management
CPEs cpe:2.3:a:oracle:warehouse_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle warehouse Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Warehouse Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:12.753Z

Reserved: 2026-08-04T22:06:34.596Z

Link: CVE-2026-70774

cve-icon Vulnrichment

Updated: 2026-08-19T12:11:24.448Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:30.320

Modified: 2026-08-24T15:50:00.290

Link: CVE-2026-70774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T05:45:03Z

Weaknesses