Sceawere

Vulnerability Detail

CVE-2026-70782UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Labor Distribution Data Compromise

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Labor Distribution
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Labor Distribution accessible data as well as unauthorized access to critical data or complete access to all Oracle Labor Distribution accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Labor Distribution accessible data as well as unauthorized access to critical data or complete access to all Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-18T21:17:31.513Z",
  "pubdate": "2026-08-18T21:17:31.513Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Internal Operations component of the Oracle Labor Distribution product of Oracle E-Business Suite, affecting supported versions 12.2.3 through 12.2.15. This security flaw enables a low-privileged attacker with network access via HTTP to compromise the affected product, leading to severe impacts on both data confidentiality and data integrity. Successful exploitation allows unauthorized adversaries to execute unauthorized creation, deletion, or modification of critical data, as well as gain unauthorized access to critical data or complete access to all accessible Oracle Labor Distribution data. The vulnerability carries a CVSS 3.1 Base Score of 8.1 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N, reflecting network exploitability with low attack complexity, low privileges required, and no user interaction necessary. The business risk implications are substantial, as compromised integrity and confidentiality within enterprise financial and labor distribution records can lead to regulatory non-compliance, fraudulent transactions, and severe operational disruption. Mitigation requires applying official vendor patches provided by Oracle for the E-Business Suite ecosystem, coupled with strict access control enforcement and network segmentation to limit exposure of the Internal Operations component.",
  "technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle Labor Distribution, a module integrated into Oracle E-Business Suite. The affected software versions comprise 12.2.3 through 12.2.15. The vulnerability manifests as an improper authorization or inadequate input validation flaw within the application logic, allowing authenticated users with low privileges to bypass intended security boundaries over the network via the HTTP protocol.\nThe attack vector is network-based (AV:N), meaning the attacker does not require physical access to the target system and can interact with the vulnerable Oracle E-Business Suite instance remotely. The attack complexity is rated as low (AC:L), indicating that the conditions required to successfully exploit the flaw are straightforward and do not rely on complex race conditions or unpredictable environmental factors. Although the attacker must possess low privileges (PR:L)—implying valid user credentials within the Oracle E-Business Suite environment—no user interaction (UI:N) is required, meaning the target operation executes deterministically without social engineering or victim participation.\nDuring the attack flow, a malicious actor leverages their low-privileged network access to send specially crafted HTTP requests targeting the vulnerable Internal Operations component of Oracle Labor Distribution. Because the application fails to adequately validate or restrict user permissions against sensitive backend functions and data sets, the request successfully bypasses access controls. This grants the attacker the ability to interact with application logic in an unauthorized manner.\nThe post-exploitation impact spans both confidentiality and integrity (C:H/I:H/A:N, Scope: Unchanged). In terms of confidentiality, the attacker achieves unauthorized access to critical data or complete access to all data accessible within Oracle Labor Distribution, potentially exposing sensitive employee compensation, payroll allocations, and financial records. In terms of integrity, the attacker can execute unauthorized creation, deletion, or modification of critical data, allowing malicious alteration of labor distribution records. The availability impact remains null (A:N), as the exploitation vector does not inherently induce denial of service conditions against the underlying infrastructure."
}
CVE-2026-70782: Oracle Labor Distribution Data Compromise (HIGH Severity, CVSS: 8.1) - Sceawere