Description
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Product Diagnostic Tools component of Oracle Order Management, part of Oracle E-Business Suite. A low-privileged attacker with network access via HTTP can exploit the flaw to compromise the application and eventually take control. The attacker can read, modify, and delete Order Management data and fully manipulate the instance, resulting in a complete takeover. This is reflected in the CVSS 3.1 score of 7.5, indicating high confidentiality, integrity, and availability impacts.

Affected Systems

Oracle Corporation’s Oracle Order Management product, versions 12.2.3 through 12.2.15, is affected. The flaw is confined to the Product Diagnostic Tools component of the suite. No other versions or components are identified as impacted.

Risk and Exploitability

The CVSS base score of 7.5 classifies the issue as high severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector appears to be network-based via HTTP; a low-privilege attacker with network access can exploit the flaw, making it realistic for adversaries that can reach the target. Successful attacks result in full application takeover, compromising confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 22, 2026 at 06:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor patch that addresses the Product Diagnostic Tools issue for Oracle Order Management 12.2.3 through 12.2.15.
  • Restrict HTTP access to the Product Diagnostic Tools endpoints so that only trusted internal hosts can reach them, using firewall rules or network segmentation.
  • If a patch is not immediately available, disable or uninstall the Product Diagnostic Tools component to reduce the attack surface.

Generated by OpenCVE AI on August 22, 2026 at 06:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Access Exploitation in Oracle Order Management Product Diagnostic Tools

Sat, 22 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Diagnostic Tools in Oracle Order Management
Weaknesses CWE-284

Sat, 22 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Fri, 21 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Diagnostic Tools in Oracle Order Management
Weaknesses CWE-284

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Oracle Order Management Takeover
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Oracle Order Management Takeover
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle order Management
CPEs cpe:2.3:a:oracle:order_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle order Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T02:47:30.189Z

Reserved: 2026-08-04T22:06:34.606Z

Link: CVE-2026-70930

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:50.983

Modified: 2026-08-28T14:44:27.630

Link: CVE-2026-70930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T06:45:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function