Sceawere

Vulnerability Detail

CVE-2026-70772UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Warehouse Management Information Disclosure Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Warehouse Management
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Warehouse Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Warehouse Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T21:17:30.017Z",
  "pubdate": "2026-08-18T21:17:30.017Z",
  "executiveSummary": "An unauthenticated information disclosure vulnerability affects the Oracle Warehouse Management product of Oracle E-Business Suite, specifically within the Internal Operations component across supported versions 12.2.3 through 12.2.15.\nThis remotely exploitable security flaw allows an external attacker with network access via HTTP to compromise the target application without requiring any authentication, user interaction, or elevated privileges.\nSuccessful exploitation of this vulnerability directly impacts system confidentiality, granting the unauthorized actor complete access to sensitive data accessible within Oracle Warehouse Management.\nGiven the network vector and low attack complexity, the risk implications are severe for organizations running vulnerable instances, as malicious actors can harvest critical enterprise data without leaving authentication footprints.\nRemediation requires applying the appropriate vendor-supplied patches provided by Oracle to secure the affected Internal Operations components.",
  "technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle Warehouse Management, part of the Oracle E-Business Suite framework, impacting software versions 12.2.3 through 12.2.15.\nAccording to the CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the security defect is exposed via the network attack vector (AV:N), meaning it can be exploited remotely over HTTP without local access requirements.\nThe attack complexity is rated as low (AC:L), indicating that the targeted endpoints lack robust defensive checks or robust input validation mechanisms to impede automated or manual exploitation attempts.\nFurthermore, the vulnerability requires no privileges (PR:N) and no user interaction (UI:N), allowing unauthenticated threat actors to directly interact with the vulnerable HTTP endpoints.\nThe attack flow proceeds as follows: an external attacker crafts an unauthenticated HTTP request targeting vulnerable endpoints within the Internal Operations component of Oracle Warehouse Management.\nDue to improper handling of request parameters or missing access control enforcement within the affected component, the application processes the request and returns unauthorized sensitive data in the HTTP response body.\nThe scope remains unchanged (S:U), meaning the vulnerability is strictly confined to the Oracle Warehouse Management component and does not inherently breach underlying operating system boundaries.\nThe post-exploitation impact is characterized entirely by a high confidentiality breach (C:H), resulting in unauthorized access to critical data or complete exposure of all information accessible to the Oracle Warehouse Management module.\nIntegrity (I:N) and Availability (A:N) impacts are none, as the vulnerability does not facilitate data modification, deletion, or denial of service conditions."
}
CVE-2026-70772: Oracle Warehouse Management Information Disclosure Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere