Description
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Document Management and Collaboration accessible data as well as unauthorized access to critical data or complete access to all Oracle Document Management and Collaboration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Attachments component of Oracle Document Management and Collaboration allows a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data. Successful exploitation can lead to unauthorized modification of attachments or complete access to all data stored in the system. The weakness, a Broken Access Control flaw (CWE-284), results in loss of confidentiality and integrity but does not affect availability. CVSS 3.1 score of 8.1 reflects high severity with low attack complexity and little privilege requirement.

Affected Systems

Oracle Document Management and Collaboration, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The fix is available in the July 2026 CPU update.

Risk and Exploitability

The CVSS base score of 8.1 indicates a high risk posture. EPSS of less than 1 % suggests that the likelihood of live exploitation is currently very low, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to be in the network and possess a low‑privileged user account to reach the HTTP endpoints that handle attachments, which is the most likely attack vector inferred from the description.

Generated by OpenCVE AI on August 4, 2026 at 05:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the July 2026 CPU patch that updates Oracle Document Management and Collaboration to a version that fixes the attachment handling issue.
  • Restrict HTTP access to the Document Management servers by limiting it to trusted IP ranges and enforce least privileged accounts for attachment operations.
  • Enable comprehensive logging for attachment creation, deletion, and modification, and monitor these logs for suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Access Enables Unauthorized Modification of Attachments in Oracle Document Management

Mon, 27 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Unauthorized Data Modification in Oracle Document Management and Collaboration

Fri, 24 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Unauthorized Data Modification in Oracle Document Management and Collaboration

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Document Management and Collaboration accessible data as well as unauthorized access to critical data or complete access to all Oracle Document Management and Collaboration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle document Management And Collaboration
CPEs cpe:2.3:a:oracle:document_management_and_collaboration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle document Management And Collaboration
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Document Management And Collaboration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:07:40.129Z

Reserved: 2026-05-18T15:55:10.317Z

Link: CVE-2026-47028

cve-icon Vulnrichment

Updated: 2026-07-23T16:16:02.447Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses