Sceawere
Vulnerability Detail
CVE-2026-61041Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Demantra Remote Takeover Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Demantra Demand Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demantra Demand Management. While the vulnerability is in Oracle Demantra Demand Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demantra Demand Management. While the vulnerability is in Oracle Demantra Demand Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-07-21T22:18:35.047Z",
"pubdate": "2026-07-21T22:18:35.047Z",
"executiveSummary": "This vulnerability affects Oracle Demantra Demand Management, a core component of the Oracle Supply Chain suite, specifically within the Product Security module.\nThe flaw allows a low-privileged, authenticated attacker to achieve full system compromise via network-based HTTP exploitation.\nDue to the nature of the vulnerability, it exhibits a significant scope change (S:C), meaning a successful compromise of the Demantra application can facilitate unauthorized access or manipulation of interconnected or downstream enterprise systems.\nThe vulnerability is rated with a critical CVSS 3.1 Base Score of 9.9, reflecting its high impact on the Confidentiality, Integrity, and Availability of the target environment.\nSuccessful exploitation grants an attacker full control over the application, potentially leading to unauthorized data extraction, modification of sensitive supply chain configurations, and total service disruption.\nThe ease of exploitation (AC:L) and the lack of required user interaction (UI:N) make this a high-priority risk for organizations utilizing affected versions 12.2.3 through 12.2.15.",
"technicalDetails": "The vulnerability resides within the Product Security component of Oracle Demantra Demand Management. The root cause pertains to an insecure implementation within the application's security framework, which fails to adequately validate or sanitize user-supplied input during remote HTTP interactions.\nThe exploit vector is remotely accessible via standard HTTP protocols. An attacker with low-privileged credentials can leverage this flaw to bypass established security controls and execute arbitrary operations with elevated privileges. Because the vulnerability involves a scope change (S:C), the impact is not localized to the Demantra instance itself; rather, it allows the attacker to traverse trust boundaries and manipulate the integrity of the broader Oracle Supply Chain infrastructure.\nThe attack flow typically initiates by the attacker identifying an endpoint within the Product Security module that fails to enforce strict access control or input validation. By crafting a malicious HTTP request, the attacker can trigger a code execution sequence. The low complexity (AC:L) suggests that no advanced technical maneuvering—such as race conditions or complex cryptographic bypasses—is required, allowing for reliable and repeatable exploitation.\nUpon successful invocation of the vulnerable function, the payload operates within the context of the application's service account. Given the application's role in supply chain management, this provides the attacker with a vantage point to intercept sensitive demand data, modify forecasts, or manipulate administrative configurations. The 'takeover' classification implies that the attacker gains sufficient control to execute arbitrary code or commands on the underlying host, thereby subverting the confidentiality, integrity, and availability of the affected system entirely.\nThe vulnerability affects all versions of Oracle Demantra Demand Management from 12.2.3 up to and including 12.2.15. The absence of user interaction requirements means that once an attacker establishes a low-privileged session, they can achieve immediate impact without needing to deceive or interact with authorized users of the system.\nPost-exploitation, the attacker may maintain persistence within the environment, escalate privileges across the network, or pivot to integrated Oracle applications, as the initial compromise provides a trusted entry point within the organizational perimeter."
}