Description
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Complex Maintenance, Repair and Overhaul permits a low‑privileged attacker with network access through HTTP to compromise the system. Successful exploitation results in full takeover, leading to confidentiality, integrity, and availability losses. Based on the description, it can be inferred that the flaw may involve improper access control or authentication mechanisms, but the specific weakness type is not explicitly stated.

Affected Systems

The affected product is Oracle Complex Maintenance, Repair and Overhaul, part of Oracle E‑Business Suite Internal Operations. Versions 12.2.3 through 12.2.15 are impacted. Users running these releases should verify their environment and consult Oracle for supported fixes.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high impact vulnerability, while the EPSS below 1 % and the absence from the CISA KEV catalog suggest low exploitation probability. Based on the description, the likely attack path involves an unauthenticated or low‑privileged HTTP session that may bypass access controls to execute arbitrary commands, but the exact vulnerability mechanism is not documented.

Generated by OpenCVE AI on June 17, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Oracle support to obtain the latest security patch for Oracle Complex Maintenance, Repair and Overhaul and upgrade to a version beyond 12.2.15.
  • Restrict HTTP access to the affected component by implementing network segmentation or firewall rules so that only trusted administrators can reach the application.
  • Enable audit logging and monitoring of all administrative actions on the system, and review logs regularly for suspicious activity indicative of compromise.

Generated by OpenCVE AI on June 17, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle complex Maintenance, Repair, And Overhaul
Vendors & Products Oracle complex Maintenance, Repair, And Overhaul

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle complex Maintenance Repair And Overhaul
CPEs cpe:2.3:a:oracle:complex_maintenance__repair_and_overhaul:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle complex Maintenance Repair And Overhaul
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Complex Maintenance, Repair, And Overhaul Complex Maintenance Repair And Overhaul
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-16T19:27:56.716Z

Reserved: 2026-05-18T15:55:10.312Z

Link: CVE-2026-46934

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T00:15:16Z

Weaknesses

No weakness.