Description
Vulnerability in the Oracle Common Application Components product of Oracle E-Business Suite (component: Oracle Common Modules). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Application Components. While the vulnerability is in Oracle Common Application Components, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Application Components accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Application Components accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Application Components. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L).
Published: 2026-07-21
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Common Application Components allows a low‑privileged attacker with network access over HTTP to perform unauthorized creation, deletion or modification of data stored in the component. The flaw effectively bypasses access control checks, compromising confidentiality, integrity, and limiting availability of critical application data. This flaw does not require elevated privileges but requires the attacker to possess a low‑privilege account or credential to access the component.

Affected Systems

Oracle Common Application Components within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are impacted.

Risk and Exploitability

The CVSS 3.1 base score of 8.4 indicates high severity, with impacts on confidentiality, integrity, and availability. The EPSS is less than 1 %, implying a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Attackers would typically exploit HTTP traffic, leveraging the low‑privilege breach to change data or trigger a partial denial of service; the scope change enables broader impact beyond the immediate component.

Generated by OpenCVE AI on August 4, 2026 at 16:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch or update when available.
  • Restrict HTTP traffic to the component by configuring firewalls or network segmentation to accept only trusted sources.
  • Enforce least privilege on accounts interacting with the component and audit permissions to thwart unauthorized data manipulation.

Generated by OpenCVE AI on August 4, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low‑Privilege HTTP Access in Oracle Common Application Components

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low‑Privilege HTTP Access in Oracle Common Application Components

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial DoS via Low‑Privilege HTTP Attack in Oracle Common Application Components
Weaknesses CWE-269

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle common Applications
Vendors & Products Oracle common Applications

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial DoS via Low‑Privilege HTTP Attack in Oracle Common Application Components
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Common Application Components product of Oracle E-Business Suite (component: Oracle Common Modules). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Application Components. While the vulnerability is in Oracle Common Application Components, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Application Components accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Application Components accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Application Components. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle common Application Components
CPEs cpe:2.3:a:oracle:common_application_components:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle common Application Components
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Common Application Components Common Applications E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T14:56:31.758Z

Reserved: 2026-07-08T15:51:55.577Z

Link: CVE-2026-60677

cve-icon Vulnrichment

Updated: 2026-07-28T13:41:02.699Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:08.680

Modified: 2026-08-06T14:59:14.243

Link: CVE-2026-60677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses