Description
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Enterprise Asset Management’s Work Definition Issues component permits a low‑privileged user with network access via HTTPS to perform unauthorized updates, inserts, deletes, or reads of certain data. The vulnerability can affect confidentiality and integrity by allowing data tampering and partial data disclosure, as quantified by a CVSS 3.1 base score of 5.4.

Affected Systems

Oracle Enterprise Asset Management (Oracle E‑Business Suite) versions 12.2.3 through 12.2.15 are impacted. Users of these releases should verify whether they are running a vulnerable build and check Oracle’s official CPU announcement for applicable patches.

Risk and Exploitability

The CVSS score indicates moderate severity, and the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The CVE is not listed in CISA’s KEV catalog. The likely attack path involves a remote attacker forging HTTPS requests to the vulnerable endpoint; no elevated privileges or prior authentication are required beyond those normally granted to a local user. Because the issue can lead to both modification and read access, it poses a tangible risk to data integrity and confidentiality for affected organizations.

Generated by OpenCVE AI on August 4, 2026 at 03:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that addresses the Work Definition Issues flaw
  • Restrict HTTPS access to Oracle Enterprise Asset Management to known, trusted IP addresses or network segments
  • Review and audit existing Work Definition data for integrity anomalies and re‑establish any inadvertently granted privileges

Generated by OpenCVE AI on August 4, 2026 at 03:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTPS data manipulation in Oracle Enterprise Asset Management

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTPS data manipulation in Oracle Enterprise Asset Management

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Low Privilege HTTPS Access in Oracle Enterprise Asset Management

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Low Privilege HTTPS Access in Oracle Enterprise Asset Management
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Work Definition Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle enterprise Asset Management
CPEs cpe:2.3:a:oracle:enterprise_asset_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Asset Management
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Enterprise Asset Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:30:32.161Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60588

cve-icon Vulnrichment

Updated: 2026-07-27T15:30:23.193Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses