Executive brief
Oracle Order Management, a core component of Oracle E-Business Suite used to process and manage customer orders, contains a vulnerability that allows authenticated users with low privileges to access and modify sensitive order data via the network. An attacker with low-level access could read confidential order information or alter order records without authorization, potentially disrupting order fulfillment and exposing customer data.
Technical details
This vulnerability exists in the Enterprise Command Center component of Oracle Order Management (V16) and is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability requires authentication (PR:L) and allows unauthorized read access to critical data and partial write access (insert/update/delete) to Order Management data. The attack vector is network-based with no user interaction required. Exploitation can result in high-impact confidentiality breaches and limited integrity violations. Patch status and mitigation details are not provided in the available advisory text.
Affected products
- Oracle Order Management V16
Timeline
- 2026-09-15: disclosed