Description
Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Content Manager accessible data as well as unauthorized read access to a subset of Oracle Content Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Content Manager. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An easily exploitable weakness in Oracle Content Manager allows an attacker with a low‑privilege account and network access to perform unauthorized create, read, update, and delete operations against data stored in the system, as well as to trigger a partial denial of service. The impact spans confidentiality, integrity, and availability of the data managed by the Content Manager component.

Affected Systems

Oracle Content Manager, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15. The vulnerability resides in the Cover Letter component of the product.

Risk and Exploitability

The CVSS base score of 6.3 signals a moderate severity, while the EPSS value of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an active HTTP session and a recognized low‑privilege account; the attacker can then bypass authorization controls to alter or read data and cause a limited service disruption.

Generated by OpenCVE AI on August 2, 2026 at 21:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Content Manager to the latest patch or CPU release referenced in the Oracle security alert
  • Configure the system to enforce least‑privilege access and disable any unused content management features
  • Continuously monitor access logs for unauthorized read or write activity and audit all content‑management operations to detect potential misuse

Generated by OpenCVE AI on August 2, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Oracle Content Manager Low‑Privilege Authorization Bypass Allowing Data Modification and Partial Denial of Service

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Oracle Content Manager Low‑Privilege Authorization Bypass Allowing Data Modification and Partial Denial of Service

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Partial Denial of Service via Low‑Privilege Network Attack in Oracle Content Manager
Weaknesses CWE-200
CWE-284
CWE-285

Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Partial Denial of Service via Low‑Privilege Network Attack in Oracle Content Manager
Weaknesses CWE-200
CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Cover Letter). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Content Manager accessible data as well as unauthorized read access to a subset of Oracle Content Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Content Manager. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle content Manager
CPEs cpe:2.3:a:oracle:content_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle content Manager
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Content Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:20:16.803Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60574

cve-icon Vulnrichment

Updated: 2026-07-27T15:19:37.609Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function