Sceawere

Vulnerability Detail

CVE-2026-70833UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Landed Cost Management Access Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Landed Cost Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Landed Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Landed Cost Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Landed Cost Management accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Landed Cost Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Landed Cost Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Landed Cost Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-18T21:17:38.660Z",
  "pubdate": "2026-08-18T21:17:38.660Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Internal Operations component of Oracle Landed Cost Management, part of the Oracle E-Business Suite. Affected supported product versions include 12.2.3 through 12.2.15. This security flaw allows a low-privileged attacker with network access via the HTTP protocol to compromise the affected application.\nSuccessful exploitation of this vulnerability can result in unauthorized access to critical data, as well as complete access to all data accessible within Oracle Landed Cost Management. Additionally, the vulnerability permits unauthorized update, insert, or delete access to a subset of the accessible data within the application.\nThe severity of this issue is reflected in a CVSS 3.1 Base Score of 7.1, with specific impacts on confidentiality and integrity. The attack vector is network-based, requiring low privileges and no user interaction, making it a significant risk for organizations utilizing vulnerable versions of Oracle E-Business Suite.",
  "technicalDetails": "The vulnerability resides in the Internal Operations component of Oracle Landed Cost Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The architectural flaw allows unauthorized data exposure and modification capabilities due to insufficient access controls or improper authorization enforcement within the affected application logic.\nExploitation of this vulnerability requires network connectivity via the HTTP protocol. An attacker must possess low privileges within the application environment to successfully initiate an attack. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N) indicates that the attack complexity is low (AC:L), user interaction is not required (UI:N), and the scope remains unchanged (S:U).\nThe attack flow proceeds as follows: First, the low-privileged attacker establishes a network connection to the Oracle Landed Cost Management application via HTTP. Second, the attacker leverages their authenticated session to interact with vulnerable internal functions within the Internal Operations component. Because the application fails to adequately enforce authorization boundaries, the attacker is able to bypass intended access restrictions.\nPost-exploitation impacts include the complete compromise of confidentiality regarding critical data accessible to Oracle Landed Cost Management, alongside unauthorized data manipulation capabilities affecting integrity. Specifically, the attacker gains the ability to execute unauthorized insert, update, and delete operations against a subset of the application's accessible data, while availability (A:N) remains unaffected by this specific vulnerability vector."
}
CVE-2026-70833: Oracle Landed Cost Management Access Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere