Sceawere

Vulnerability Detail

CVE-2026-70760UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Order Management Diagnostic Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Order Management
Attack Type
Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Order Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Order Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T21:17:28.593Z",
  "pubdate": "2026-08-18T21:17:28.593Z",
  "executiveSummary": "A vulnerability has been identified within the Product Diagnostic Tools component of Oracle Order Management, affecting Oracle E-Business Suite versions 12.2.3 through 12.2.15. This security flaw allows a remote, low-privileged attacker with network access via HTTP to execute unauthorized operations against the target system.\nThe vulnerability presents significant risk due to its scope-changing nature, meaning that successful exploitation within Oracle Order Management can heavily impact additional integrated products and underlying systems.\nExploitation requires high attack complexity and low privileges, but does not necessitate user interaction. Successful attacks compromise data confidentiality by granting unauthorized access to critical data or complete access to all Oracle Order Management accessible data. Furthermore, attackers can achieve unauthorized update, insert, or delete access to a subset of accessible data, leading to potential data integrity degradation.\nOrganizations utilizing affected versions of Oracle E-Business Suite must prioritize remediation to mitigate the risks associated with unauthorized data exposure and manipulation.",
  "technicalDetails": "The vulnerability resides in the Product Diagnostic Tools component of Oracle Order Management within Oracle E-Business Suite, specifically impacting versions 12.2.3 to 12.2.15.\nThe flaw is exposed over the network via the HTTP protocol, allowing remote threat actors to interact with the vulnerable diagnostic interfaces.\nAlthough the entry point is localized to Oracle Order Management, the vulnerability features a scope change (S:C), indicating that successful exploitation can transcend the security boundaries of the immediate application and significantly impact additional connected products within the E-Business Suite ecosystem.\nExploitation prerequisites dictate that the attacker must possess low privileges (PR:L) within the application and establish network connectivity (AV:N). Additionally, the attack complexity is rated as high (AC:H), implying that successful execution may require specific race conditions, precise timing, or specialized configurations by the threat actor. No user interaction (UI:N) is required for the attack to succeed.\nThe attack flow proceeds as follows: First, the authenticated low-privileged attacker leverages network access over HTTP to target the vulnerable Product Diagnostic Tools within Oracle Order Management. Second, due to insufficient input validation, authorization enforcement, or logic flaws within the diagnostic component, the attacker bypasses standard access controls. Third, leveraging the scope change characteristic, the attacker propagates the attack vector beyond the primary application context to impact wider architectural domains. Finally, the attacker executes unauthorized read operations to obtain critical or complete access to sensitive data, alongside unauthorized data manipulation capabilities including insert, update, and delete operations against select accessible data sets.\nThe resulting impact is quantified by a CVSS 3.1 Base Score of 7.1, driven by high confidentiality impacts (C:H) and low integrity impacts (I:L), with availability remaining unaffected (A:N)."
}
CVE-2026-70760: Oracle Order Management Diagnostic Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere