Executive brief
Oracle Order Management is a module within Oracle E-Business Suite that handles order processing and fulfillment. An attacker with low-level access to the network can exploit a vulnerability in the Product Diagnostic Tools component to read, modify, or delete order data without authorization. This could expose sensitive customer orders, financial information, and lead to operational disruption or regulatory compliance violations.
Technical details
The vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management (versions 12.2.4–12.2.15). It is easily exploitable and requires only low-level privileges and network access via HTTP; no user interaction is required. A low-privileged attacker can gain unauthorized read and write access to critical data within the Order Management module. The vulnerability impacts both confidentiality (unauthorized data disclosure) and integrity (unauthorized creation, deletion, or modification of data). Oracle has released patches as part of their security advisory.
Affected products
- Oracle E-Business Suite Order Management 12.2.4–12.2.15
Timeline
- 2026-09-15: disclosed