Description
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the authorization component of Oracle Public Sector Financials (International) allows an attacker who is not privileged but has network access to HTTP endpoints to compromise the application. The flaw can lead to complete takeover of the system, resulting in loss of confidentiality, integrity, and availability of the financial data it manages. This remains a serious issue, classified as high severity with a CVSS score of 8.8, and would grant the attacker full control over the application once exploited.

Affected Systems

The affected product is Oracle Public Sector Financials (International), part of Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 are impacted.

Risk and Exploitability

The CVSS vector indicates network access (AV:N), low attack complexity (AC:L), low privilege (PR:L), no user interaction (UI:N), and unresolved scope, with high impact on confidentiality, integrity, and availability. The EPSS score is under 1 %, indicating very low exploitation probability as of the time of this analysis, and the flaw is not yet listed in CISA’s KEV catalog. Nonetheless, because the vulnerability permits a full takeover, it should be treated as critical and prioritized for remediation. Attackers with simple HTTP access can exploit the flaw without elevated privileges, meaning the risk is significant even for moderately exposed environments.

Generated by OpenCVE AI on June 17, 2026 at 18:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch for Oracle Public Sector Financials (International) or upgrade to a version newer than 12.2.15
  • Restrict network exposure of the application by guarding HTTP ports with a firewall or VPN so that only trusted hosts can reach the service
  • Enforce strict site‑level authentication and audit logs to detect unauthorized access attempts promptly

Generated by OpenCVE AI on June 17, 2026 at 18:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Public Sector Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T17:36:51.844Z

Reserved: 2026-05-18T15:55:10.314Z

Link: CVE-2026-46967

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T03:00:16Z

Weaknesses

No weakness.