Junglewise Threat Intelligence

CVE-2026-62445: Oracle Order Management data compromise in Product Diagnostic Tools

CVE-2026-62445 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management, a suite used by businesses to manage sales and fulfillment processes. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive business data. This could lead to significant data breaches or the disruption of order processing operations.

Technical details

This vulnerability affects the Product Diagnostic Tools component of Oracle Order Management within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation grants the attacker unauthorized capabilities to create, delete, or modify critical data, as well as full read access to all data accessible by the Order Management module. The vulnerability has a CVSS 3.1 base score of 8.1, impacting both confidentiality and integrity, though it does not directly impact service availability. Affected versions range from 12.2.4 through 12.2.15.

Affected products

  • Oracle Order Management (Product Diagnostic Tools) 12.2.4-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update July 2026

References