Oracle Order Management vulnerabilities
10 known vulnerabilities affecting oracle/order_management.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-60872P2HIGHCVSS 8.8≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-60872 [HIGH] CWE-269 CVE-2026-60872: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can r
nvd
CVE-2026-62445P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62445 [HIGH] CWE-284 CVE-2026-62445: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can r
nvd
CVE-2026-70930P3HIGHCVSS 7.5≥ 12.2.3, ≤ 12.2.152026-08-18
CVE-2026-70930 [HIGH] CWE-306 CVE-2026-70930: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can
nvd
CVE-2026-61115P3HIGHCVSS 7.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61115 [HIGH] CWE-284 CVE-2026-61115: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can
nvd
CVE-2026-61112P3MEDIUMCVSS 6.5≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61112 [MEDIUM] CWE-200 CVE-2026-61112: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can
nvd
CVE-2026-70760P3HIGHCVSS 7.1≥ 12.2.3, ≤ 12.2.152026-08-18
CVE-2026-70760 [HIGH] CWE-284 CVE-2026-70760: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order M
nvd
CVE-2026-60864P3MEDIUMCVSS 6.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-60864 [MEDIUM] CWE-200 CVE-2026-60864: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order M
nvd
CVE-2026-60862P3MEDIUMCVSS 6.8≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-60862 [MEDIUM] CWE-284 CVE-2026-60862: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order
nvd
CVE-2026-70932P3HIGHCVSS 7.2≥ 12.2.3, ≤ 12.2.152026-08-18
CVE-2026-70932 [HIGH] CWE-284 CVE-2026-70932: Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Management executes to compromise Oracle Order Management.
nvd
CVE-2018-2954P4HIGHCVSS 7.0v12.1.1v12.1.2+6 more2018-07-18
CVE-2018-2954 [HIGH] CVE-2018-2954: Vulnerability in the Oracle Order Management component of Oracle E-Business Suite (subcomponent: Pro
Vulnerability in the Oracle Order Management component of Oracle E-Business Suite (subcomponent: Product Diagnostic Tools). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Order Management ex
nvd