Executive brief
A vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management, a core module of the Oracle E-Business Suite used for managing sales and fulfillment. A high-privileged attacker could exploit this flaw to gain full control over the Order Management system. This could lead to the unauthorized access, modification, or deletion of sensitive customer orders and business data, potentially disrupting supply chain operations.
Technical details
A vulnerability in the Oracle Order Management product of Oracle E-Business Suite, specifically within the Product Diagnostic Tools component, allows for a complete system compromise. The flaw is categorized as easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation grants the attacker full control over Confidentiality, Integrity, and Availability (CIA) of the affected component. The vulnerability impacts versions 12.2.3 through 12.2.15. Remediation information is typically provided in the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle Corporation Oracle Order Management (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD