Sceawere

Vulnerability Detail

CVE-2026-70947UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Purchasing Unauthorized Data Access

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Purchasing
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Purchasing accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T21:17:52.930Z",
  "pubdate": "2026-08-18T21:17:52.930Z",
  "executiveSummary": "An unauthorized, remotely exploitable vulnerability affects the Oracle Purchasing product within Oracle E-Business Suite, specifically residing within the Other issue component. This security flaw enables unauthenticated threat actors with network access via HTTP to compromise the affected application.\nSuccessful exploitation of this vulnerability yields severe confidentiality impacts, granting attackers unauthorized read access to critical data or complete access to all data accessible via Oracle Purchasing. The vulnerability is characterized by a CVSS 3.1 Base Score of 7.5, reflecting its high severity due to the lack of required privileges or user interaction.\nThe risk implications include significant data exposure of sensitive procurement and enterprise financial information stored within the Oracle E-Business Suite ecosystem. Because the attack vector is network-based and requires no authentication or user interaction, external threat actors can target exposed instances directly, making prompt remediation or patch application critical for maintaining organizational data security and compliance posture.",
  "technicalDetails": "The vulnerability resides in the Oracle Purchasing product of Oracle E-Business Suite, specifically affecting the Other issue component across supported versions 12.2.3 through 12.2.15. The flaw permits remote, unauthenticated exploitation over the HTTP protocol, bypassing standard authorization boundaries enforced by the application layer.\nThe root cause stems from improper access control enforcement within the vulnerable component, allowing arbitrary or unauthenticated HTTP requests to query and retrieve backend data structures associated with Oracle Purchasing. Attackers leverage standard network socket communication to transmit crafted HTTP requests directly to the exposed application endpoints without supplying valid session tokens or credentials.\nThe attack flow proceeds as follows: First, the unauthenticated attacker establishes network connectivity to the target Oracle E-Business Suite instance via HTTP. Second, the adversary crafts and transmits malicious or unvalidated HTTP requests targeting the vulnerable Oracle Purchasing component. Third, due to the absence of robust authentication and authorization checks within the affected component, the application processes the request and queries the underlying database or data repository. Finally, the application returns the requested sensitive data in the HTTP response payload, granting the attacker unauthorized access to critical enterprise information.\nThe attack vector is network-based (AV:N), with low attack complexity (AC:L), requiring zero privileges (PR:N) and no user interaction (UI:N). The scope remains unchanged (S:U), but the impact on confidentiality is high (C:H), while integrity (I:N) and availability (A:N) remain unaffected. Post-exploitation impact is strictly constrained to unauthorized data disclosure, potentially exposing procurement records, vendor details, and other sensitive corporate data handled by Oracle Purchasing."
}
CVE-2026-70947: Oracle Purchasing Unauthorized Data Access (HIGH Severity, CVSS: 7.5) - Sceawere