Sceawere
Vulnerability Detail
CVE-2026-70801UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Flow Manufacturing Data Compromise Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Flow Manufacturing
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data as well as unauthorized update, insert or delete access to some of Oracle Flow Manufacturing accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data as well as unauthorized update, insert or delete access to some of Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-08-18T21:17:34.240Z",
"pubdate": "2026-08-18T21:17:34.240Z",
"executiveSummary": "A vulnerability has been identified within the Internal Operations component of Oracle Flow Manufacturing, part of the Oracle E-Business Suite. This security flaw allows a low-privileged authenticated attacker with network access via HTTP to execute unauthorized operations against the targeted system. Specifically, the vulnerability affects supported product versions ranging from 12.2.3 to 12.2.15.\nThe risk implications are significant, as successful exploitation enables unauthorized read access to critical data or complete access to all data accessible within Oracle Flow Manufacturing. Additionally, attackers can gain unauthorized update, insert, or delete access to a subset of the accessible data, undermining data integrity and confidentiality while leaving system availability unaffected.\nAccording to the CVSS 3.1 scoring, this vulnerability receives a Base Score of 7.1 with the vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N). The exploitation requirements are minimal in terms of attack complexity and user interaction, relying primarily on low privileges and network accessibility to initiate malicious requests.",
"technicalDetails": "The vulnerability resides in the Internal Operations component of Oracle Flow Manufacturing within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The root cause stems from insufficient access controls and inadequate authorization enforcement during the processing of HTTP-based requests handled by the vulnerable component.\nExploitation of this vulnerability requires the attacker to possess low-level valid credentials within the application ecosystem, satisfying baseline authentication requirements. Network exposure is present via the HTTP protocol, allowing remote attackers who have reached the application tier to interact directly with the vulnerable endpoints without requiring user interaction or complex preconditions.\nThe attack flow proceeds in a sequential manner. First, the authenticated attacker crafts a malicious HTTP request targeting the vulnerable Internal Operations functionality within Oracle Flow Manufacturing. Because the application fails to adequately validate whether the requesting low-privileged user is authorized to access or modify specific operational data sets, the backend server processes the request.\nDuring payload execution, the application returns sensitive data streams to the attacker, resulting in unauthorized access to critical data or complete exposure of data accessible to the module. Concurrently, the processing of manipulated parameters allows the attacker to execute unauthorized data insertion, modification, or deletion against vulnerable database tables or internal data structures tied to the component.\nPost-exploitation impact is characterized by a severe compromise of confidentiality due to widespread data exfiltration, coupled with a localized loss of data integrity resulting from unauthorized database mutations. The absence of availability impact indicates that the vulnerability does not directly facilitate denial-of-service conditions against the Oracle E-Business Suite environment."
}