Junglewise Threat Intelligence

CVE-2026-61112: Oracle Order Management information disclosure in Product Diagnostic Tools

CVE-2026-61112 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Order Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management, a suite used by businesses to manage sales orders and fulfillment. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could lead to the exposure of critical order information or proprietary data stored within the Oracle E-Business Suite environment.

Technical details

This vulnerability affects the Product Diagnostic Tools component of Oracle Order Management within the Oracle E-Business Suite. It is classified as an information disclosure flaw that can be exploited by a low-privileged attacker with network access via HTTP. The exploit does not require user interaction and has a low complexity, allowing an attacker to bypass intended confidentiality restrictions. Successful exploitation results in unauthorized access to critical data or complete access to all data accessible by the Oracle Order Management module. The issue affects versions 12.2.3 through 12.2.15 and was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Order Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats