CVE-2026-70700: High severity Oracle Oracle E-Business Suite (Oracle Payables) vulnerability
Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payables. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Payables. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite (Oracle Payables) - Internal Operationsto a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15
Event History
Frequently Asked Questions
Which deployments are affected?
Oracle Payables in Oracle E-Business Suite supported versions 12.2.3 through 12.2.15 is affected, specifically the Internal Operations component.
What access does an attacker need?
An unauthenticated attacker needs network access to the affected Oracle Payables service over HTTP. No credentials or user interaction are required.
What is the practical impact of exploitation?
Successful exploitation can cause Oracle Payables to hang or crash repeatedly, resulting in a complete denial of service. The provided CVSS vector indicates no confidentiality or integrity impact.