Sceawere

Vulnerability Detail

CVE-2026-70800UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle SDP Number Portability Privilege Compromise

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle SDP Number Portability
Attack Type
Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes to compromise Oracle SDP Number Portability. While the vulnerability is in Oracle SDP Number Portability, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SDP Number Portability accessible data as well as unauthorized read access to a subset of Oracle SDP Number Portability accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SDP Number Portability.
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SDP Number Portability executes to compromise Oracle SDP Number Portability. While the vulnerability is in Oracle SDP Number Portability, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SDP Number Portability accessible data as well as unauthorized read access to a subset of Oracle SDP Number Portability accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SDP Number Portability. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-08-18T21:17:34.103Z",
  "pubdate": "2026-08-18T21:17:34.103Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Internal Operations component of Oracle SDP Number Portability in Oracle E-Business Suite versions 12.2.3 through 12.2.15. This vulnerability permits a highly privileged attacker who has obtained local logon access to the underlying infrastructure where Oracle SDP Number Portability executes to successfully compromise the target product.\nAlthough the vulnerable code resides specifically within Oracle SDP Number Portability, successful exploitation induces a scope change that can significantly impact additional co-located or dependent products within the architecture. The direct security implications include unauthorized creation, deletion, and modification access to critical data or all data accessible by Oracle SDP Number Portability, alongside unauthorized read access to a subset of accessible data. Furthermore, attackers can induce a partial denial of service (partial DoS) against the application.\nThe vulnerability carries a CVSS 3.1 Base Score of 7.3 with the vector (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L), emphasizing that while physical or local access with high privileges is required, the execution complexity remains low and the resultant impact spans multiple security triads.",
  "technicalDetails": "The vulnerability is localized to the Internal Operations component of the Oracle SDP Number Portability product within Oracle E-Business Suite, affecting software versions 12.2.3 through 12.2.15. The root cause stems from insufficient access controls, inadequate input validation, or improper handling of privileged internal operations within the infrastructure executing the software binaries.\nTo initiate an attack, the threat actor must first achieve local interactive access or execute commands on the underlying operating system infrastructure where Oracle SDP Number Portability is deployed and operating. Because the attack vector is local (AV:L), remote network connectivity is not required for the initial exploitation phase. Additionally, the attacker must possess high privileges (PR:H) on the host environment, allowing them to interact with internal application processes, shared memory spaces, configuration files, or local administrative interfaces.\nThe exploitation flow proceeds as follows: First, the highly privileged local attacker leverages their existing OS-level access to target the Internal Operations component of Oracle SDP Number Portability. Due to weak privilege segregation or flawed boundary enforcement within the application's internal mechanics, the attacker exploits the execution context to manipulate internal states or invoke unauthorized operational routines. Because the vulnerability exhibits a scope change (S:C), the execution breaches the intended security boundaries of Oracle SDP Number Portability, allowing the attacker's elevated capabilities to propagate to broader infrastructure or additional associated products.\nOnce the exploitation payload is executed, the post-exploitation impact materializes across confidentiality, integrity, and availability. For integrity, the attacker gains unauthorized capabilities to create, delete, and modify critical datasets or any data accessible within the scope of Oracle SDP Number Portability. For confidentiality, unauthorized read access is granted to a specific subset of accessible application data. Finally, for availability, the attacker can disrupt normal operational workflows, resulting in a partial denial of service (partial DoS) that degrades application performance or renders specific internal services unresponsive."
}
CVE-2026-70800: Oracle SDP Number Portability Privilege Compromise (HIGH Severity, CVSS: 7.3) - Sceawere