Executive brief
A vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management, a system used by businesses to manage sales and fulfillment. An attacker with basic user access can exploit this flaw to view, modify, or delete sensitive order data. Because this issue can affect other connected systems, it poses a risk to the overall integrity of the corporate business suite.
Technical details
This vulnerability affects the Product Diagnostic Tools component of Oracle Order Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. The exploit results in a 'scope change' (S:C), meaning the impact can extend beyond the Order Management application to other products. Successful exploitation grants unauthorized capabilities to read, update, insert, or delete a subset of accessible data. Users are advised to apply the relevant patches from the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Order Management (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory