Sceawere

Vulnerability Detail

CVE-2026-70932UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Order Management Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Order Management
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Management executes to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Order Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Order Management accessible data.
Vector String
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Management executes to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Order Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-18T21:17:51.213Z",
  "pubdate": "2026-08-18T21:17:51.213Z",
  "executiveSummary": "A vulnerability exists within the Product Diagnostic Tools component of Oracle Order Management in Oracle E-Business Suite versions 12.2.3 through 12.2.15. This vulnerability is classified as difficult to exploit and requires a high-privileged attacker to possess direct logon access to the underlying infrastructure where Oracle Order Management executes. Despite the local and constrained attack vector, a successful exploit introduces a scope change, meaning the impact extends beyond the immediate component to significantly affect additional products within the ecosystem.\nThe primary risk implications include unauthorized creation, deletion, or modification capabilities regarding critical data, alongside complete unauthorized access to all data accessible by Oracle Order Management. The CVSS 3.1 base score is 7.2 with high confidentiality and integrity impacts, though availability remains unaffected. Exploitation relies heavily on the attacker's pre-existing high-privileged access to the infrastructure, compounding the necessity for strict host-level security controls and rigorous access monitoring within enterprise Oracle deployments.",
  "technicalDetails": "The vulnerability resides in the Product Diagnostic Tools component of Oracle Order Management, affecting supported versions 12.2.3 to 12.2.15 of Oracle E-Business Suite. The root cause stems from insecure handling, execution, or processing logic within the diagnostic utilities when invoked within the application infrastructure. Because the flaw manifests locally, the attack vector is categorized as Local (AV:L), requiring the adversary to have already breached the perimeter and obtained local logon access to the host environment.\nThe exploitation requirements demand high privileges (PR:H) on the underlying infrastructure and low attack complexity coupled with difficult exploit conditions (AC:H), meaning successful execution requires precise environmental pre-conditions or specialized orchestration by the threat actor. No user interaction (UI:N) is required for the attack to succeed. The attack flow begins with the authenticated high-privileged user or process leveraging local infrastructure access to interact with the vulnerable Product Diagnostic Tools. By supplying maliciously crafted inputs or manipulating execution parameters within the diagnostic framework, the attacker bypasses intended boundary controls.\nDue to the scope change (S:C) characteristic of this vulnerability, the execution context transcends the boundaries of Oracle Order Management, exerting a severe security impact on additional integrated products residing within the Oracle E-Business Suite ecosystem. Post-exploitation impact encompasses unauthorized data manipulation—specifically the creation, deletion, and modification of critical operational data—as well as complete unauthorized read access to sensitive data stores accessible via the application context. The resulting compromise invalidates confidentiality and integrity guarantees for the affected and scoped-out components while leaving availability (A:N) unimpacted."
}
CVE-2026-70932: Oracle Order Management Privilege Escalation (HIGH Severity, CVSS: 7.2) - Sceawere