Description
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle’s Complex Maintenance, Repair and Overhaul component of Oracle E-Business Suite allows an attacker with low privileges to gain complete control over the application. The flaw can be triggered over HTTP and, if successfully exploited, grants the attacker full takeover of the system, compromising confidentiality, integrity, and availability of the affected environment. This aligns with CWE‑284, identifying improper access control as the underlying weakness.

Affected Systems

The affected product is Oracle Complex Maintenance, Repair and Overhaul, part of Oracle E‑Business Suite. Versions within the range 12.2.3 to 12.2.15 are vulnerable. No specific sub‑versions are identified beyond this range, and the issue is tied to the internal operations component of the application.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that real‑world exploitation is unlikely at present, yet the impact remains serious should an exploit be discovered. The vulnerability is not listed in the CISA KEV catalog, but networks with open HTTP access to Oracle Complex Maintenance, Repair and Overhaul should treat this issue with priority, as the attack vector is remote and requires only low privilege.

Generated by OpenCVE AI on June 17, 2026 at 17:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle vendor patch or upgrade for Oracle Complex Maintenance, Repair and Overhaul versions 12.2.3 through 12.2.15
  • Restrict network access to the Oracle Complex Maintenance, Repair and Overhaul HTTP interface to trusted IP ranges or apply firewall rules to block external traffic
  • Enforce strict authentication and privilege controls on the internal operations component, limiting low‑privileged users and regularly reviewing access rights

Generated by OpenCVE AI on June 17, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle complex Maintenance Repair And Overhaul
CPEs cpe:2.3:a:oracle:complex_maintenance__repair_and_overhaul:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle complex Maintenance Repair And Overhaul
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Complex Maintenance Repair And Overhaul
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-16T19:27:57.026Z

Reserved: 2026-05-18T15:55:10.312Z

Link: CVE-2026-46935

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T06:00:05Z

Weaknesses

No weakness.