Description
Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Quality product of Oracle E‑Business Suite contains a flaw that enables a low‑privileged attacker with network access via HTTP to take over the system. The vulnerability can compromise confidentiality, integrity, and availability, allowing the attacker to fully control Oracle Quality. The CVSS 3.1 vector indicates that the weakness is exploitable over the network with low effort and low privileged attacker.

Affected Systems

Affected versions range from 12.2.3 through 12.2.15 of Oracle Quality. The product resides within the Internal Operations component of Oracle E‑Business Suite and is deployed by organizations that manage Oracle Quality processes.

Risk and Exploitability

The CVSS base score of 8.8 marks this issue as high severity, and the EPSS score of less than 1% suggests that exploitation is unlikely in the near term. Nevertheless, the vulnerability is listed in Oracle’s security alert and is not part of the CISA KEV catalog. Because the flaw is remotely exploitable over HTTP without local privileges, any machine that hosts Oracle Quality and is reachable from outside the trusted network faces a serious risk of compromise.

Generated by OpenCVE AI on June 17, 2026 at 18:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch or upgrade to at least version 12.2.16 of Oracle Quality following Oracle’s recommendation in the June 2026 security alert.
  • If the patch cannot be applied immediately, isolate Oracle Quality by restricting HTTP access to trusted internal networks using firewall rules or VPN, ensuring only authorized systems can reach the service.
  • Strengthen access controls by disabling or limiting low‑privileged accounts from performing administrative functions on Oracle Quality and ensure the system’s authentication and authorization configurations are reviewed to prevent unauthorized use.

Generated by OpenCVE AI on June 17, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle quality
CPEs cpe:2.3:a:oracle:quality:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle quality
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T19:19:50.192Z

Reserved: 2026-05-18T15:55:10.313Z

Link: CVE-2026-46952

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T03:00:16Z

Weaknesses

No weakness.