Description
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Workflow executes to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-07-21
Score: 3.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Workflow in Oracle E‑Business Suite. A low‑privileged user who has local access can exploit a vulnerability that violates CWE‑284 (Improper Access Control) to alter, insert or delete data normally restricted to higher‑privileged workflow users. The attacker can also trigger a partial denial of service of the Oracle Workflow component. The impact is limited to integrity and availability for versions 12.2.3 through 12.2.15, with the flaw confined to the Workflow Notification Mailer component.

Affected Systems

The vulnerability affects Oracle Corporation’s Oracle Workflow component of Oracle E‑Business Suite, specifically the Workflow Notification Mailer. It impacts the releases from 12.2.3 through 12.2.15. Systems running these versions on infrastructure where a local low‑privileged account can log on are susceptible.

Risk and Exploitability

The CVSS base score is 3.6 and the EPSS score is less than 1 %; the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. Because the problem requires local access and low privileges, the attack surface is constrained. An attacker with a local account can log on to the host and interact with workflow data, potentially modifying entries or causing service interruptions. The risk remains comparatively low, but organizations with critical workflow processing should act promptly.

Generated by OpenCVE AI on August 4, 2026 at 04:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s security patch update announced in the July 2026 CPU advisory.
  • Disable or restrict the Workflow Notification Mailer service if the functionality is not required for business processes.
  • Enforce least‑privilege policies on the server hosting Oracle Workflow, restricting local user accounts from accessing workflow data directly.
  • Monitor database logs for unexpected INSERT, UPDATE, or DELETE operations on workflow tables and watch for failures or timeouts indicating partial denial of service activity.

Generated by OpenCVE AI on August 4, 2026 at 04:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Low-Privilege Users Can Modify Oracle Workflow Data and Cause Partial DoS

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Local Low-Privilege Users Can Modify Oracle Workflow Data and Cause Partial DoS

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Workflow executes to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle workflow
CPEs cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle workflow
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:05:38.701Z

Reserved: 2026-07-08T15:51:40.514Z

Link: CVE-2026-60144

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:41.910Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:15.050

Modified: 2026-07-28T14:07:48.623

Link: CVE-2026-60144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses