Executive brief
Oracle Order Management is a critical component of Oracle E-Business Suite that handles customer orders and order processing workflows. A vulnerability in its Product Diagnostic Tools component allows a low-privileged attacker with network access to bypass authentication controls, potentially gaining complete administrative control over the Order Management system and compromising confidential business data, transaction integrity, and system availability.
Technical details
This is a difficult-to-exploit authentication bypass vulnerability in the Product Diagnostic Tools component of Oracle Order Management (E-Business Suite versions 12.2.3 through 12.2.15). The vulnerability requires the attacker to be a low-privileged user with network access via HTTP; it does not require user interaction. Successful exploitation allows an attacker to gain complete takeover of the Oracle Order Management system, compromising confidentiality, integrity, and availability. A patch is expected to be available from Oracle's security advisory dated August 2026.
Affected products
- Oracle E-Business Suite Order Management 12.2.3 to 12.2.15
Timeline
- 2026-08-18: disclosed