Description
Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle SDP Number Portability accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SDP Number Portability. CVSS 3.1 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle SDP Number Portability component exposes a web interface that can be exploited by low‑privileged users with network access via HTTP. Attackers can perform unauthorized update, insert or delete operations on data accessible through the component, and the flaw can also be used to cause a partial denial of service. The result is a compromise of the data integrity and availability of the service.

Affected Systems

Oracle SDP Number Portability of Oracle E-Business Suite, versions 12.2.3 to 12.2.15. The affected component is part of the installation package and includes a network‑exposed HTTP endpoint.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 indicates moderate severity, with impacts on integrity and availability. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network attack over HTTP, requiring only low privileges to achieve unauthorized changes or service disruption.

Generated by OpenCVE AI on August 2, 2026 at 21:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Oracle patch or update that fixes the SDP Number Portability vulnerability.
  • Restrict HTTP access to the SDP service to trusted networks or IP ranges using firewalls or access control lists.
  • Enable auditing and monitoring for unauthorized data modification attempts and partial denial of service events.

Generated by OpenCVE AI on August 2, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Allows Unauthorized Data Modification and Partial Denial in Oracle SDP Number Portability

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Web Interface Exploit Enables Unauthorized Data Changes and Partial DoS in Oracle SDP Number Portability
Weaknesses CWE-284

Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Web Interface Exploit Enables Unauthorized Data Changes and Partial DoS in Oracle SDP Number Portability
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle SDP Number Portability product of Oracle E-Business Suite (component: Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle SDP Number Portability accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SDP Number Portability. CVSS 3.1 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle sdp Number Portability
CPEs cpe:2.3:a:oracle:sdp_number_portability:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle sdp Number Portability
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Oracle Sdp Number Portability
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:06:40.892Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60571

cve-icon Vulnrichment

Updated: 2026-07-27T15:02:45.392Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses