Impact
A privilege escalation flaw in the Product Diagnostic Tools component of Oracle Order Management allows an attacker who has high‑privileged logon access to the underlying infrastructure to compromise the application and gain unauthorized creation, deletion, or modification of critical data. The vulnerability does not require user interaction and can be abused locally by users with elevated privileges, resulting in confidentiality and integrity breaches.
Affected Systems
Affected versions are Oracle Order Management 12.2.3 through 12.2.15, part of Oracle E‑Business Suite. The flaw exists within the Order Management application and can also lead to compromise of other integrated products due to scope change.
Risk and Exploitability
The CVSS score of 7.2 reflects a high severity of confidentiality and integrity impact. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. Because the attack vector is local and requires high privileges, the risk is primarily to internal users who have the necessary access. Organizational stakeholders should treat this as an urgent patch requirement, as a successful exploit grants the attacker destructive capabilities over all data accessible to Order Management.
OpenCVE Enrichment