Executive brief
A vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management, a key module within the Oracle E-Business Suite used for managing sales and fulfillment. A high-privileged user could exploit this flaw over the network to gain unauthorized access to sensitive business data. This breach could potentially extend beyond Order Management to impact other integrated Oracle products, leading to a significant loss of data confidentiality.
Technical details
This vulnerability affects the Product Diagnostic Tools component of Oracle Order Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an information disclosure issue that allows a high-privileged attacker with network access via HTTP to compromise the system. The exploit is characterized by a 'scope change' (S:C), meaning a successful attack can impact components or data outside the immediate security scope of Oracle Order Management. The primary impact is on confidentiality, potentially resulting in unauthorized access to all data accessible by the module. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle Order Management (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory