Sceawere
Vulnerability Detail
CVE-2026-70816UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Financials for EMEA Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Financials for EMEA
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for EMEA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financials for EMEA accessible data as well as unauthorized update, insert or delete access to some of Oracle Financials for EMEA accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for EMEA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financials for EMEA accessible data as well as unauthorized update, insert or delete access to some of Oracle Financials for EMEA accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-08-18T21:17:36.347Z",
"pubdate": "2026-08-18T21:17:36.347Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Internal Operations component of Oracle Financials for EMEA, affecting supported product versions 12.2.3 through 12.2.15 of the Oracle E-Business Suite. This security flaw enables a remote, low-privileged attacker with network access via HTTP to compromise the affected application. Successful exploitation of this vulnerability results in significant security compromises, specifically yielding unauthorized access to critical data or complete access to all accessible data within Oracle Financials for EMEA. Furthermore, it permits unauthorized update, insert, or delete access to a subset of the accessible data. The severity of this vulnerability is underscored by a CVSS 3.1 Base Score of 7.1, with impact vectors concentrated on confidentiality and integrity. The attack vector is network-based with low attack complexity, requiring low privileges and no user interaction, making it a high-risk concern for organizations utilizing the impacted versions of the Oracle E-Business Suite.",
"technicalDetails": "The vulnerability resides in the Internal Operations component of Oracle Financials for EMEA within the Oracle E-Business Suite, specifically impacting software versions 12.2.3 through 12.2.15. The flaw is exposed via the HTTP protocol, granting remote network access to adversaries possessing low privileges.\nThe attack flow begins when an authenticated attacker with low privileges crafts an HTTP request targeting the vulnerable Internal Operations functionality. Due to insufficient input validation, authorization checks, or access control enforcement within the affected component, the application fails to properly restrict the user's operational scope.\nDuring exploitation, the attacker transmits malicious or unauthorized HTTP payloads directly to the vulnerable endpoints. Because the system improperly validates the boundaries of the low-privileged user's session against the requested internal operations, the application processes the request and executes unauthorized database queries or administrative logic.\nPost-exploitation impact includes severe breaches of data confidentiality and integrity. The attacker gains the capability to read critical data or achieve complete read access across all data accessible to Oracle Financials for EMEA. Additionally, the vulnerability allows the execution of unauthorized data manipulation operations, specifically insert, update, and delete actions, against select accessible data stores within the application.\nThe exploitation requirements demand network connectivity over HTTP, valid low-privileged authentication credentials, and zero user interaction. The attack complexity is rated as low, allowing reliable execution once the network path and valid credentials are established."
}