Junglewise Threat Intelligence

CVE-2026-60862: Oracle Order Management information disclosure in Product Diagnostic Tools

CVE-2026-60862 · Severity: medium · CVSS 6.8 · Published 2026-07-21

Technologies: Oracle Order Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management, a key module within the Oracle E-Business Suite used for managing sales and fulfillment. A high-privileged user could exploit this flaw over the network to gain unauthorized access to sensitive business data. This breach could potentially extend beyond Order Management to impact other integrated Oracle products, leading to a significant loss of data confidentiality.

Technical details

This vulnerability affects the Product Diagnostic Tools component of Oracle Order Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an information disclosure issue that allows a high-privileged attacker with network access via HTTP to compromise the system. The exploit is characterized by a 'scope change' (S:C), meaning a successful attack can impact components or data outside the immediate security scope of Oracle Order Management. The primary impact is on confidentiality, potentially resulting in unauthorized access to all data accessible by the module. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Order Management (E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats