Description
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in takeover of Oracle General Ledger. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle General Ledger product of Oracle E‑Business Suite contains a flaw that permits an attacker with low privileges to invoke SOAP calls over the network. This flaw results in the compromise of Oracle General Ledger and allows full control over the application, causing loss of confidentiality, integrity, and availability. The weakness stems from improper access control (CWE‑269), weak authentication (CWE‑287), and missing authorization (CWE‑306).

Affected Systems

Affected products include Oracle General Ledger within Oracle E‑Business Suite's Internal Operations component. Versions from 12.2.3 through 12.2.15 are impacted. No other version information is provided.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates high severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation at this time, and the vulnerability is not currently listed in the CISA KEV catalog. The flaw requires network connectivity to the SOAP service and minimal user privileges; therefore, any system exposing the SOAP endpoint to the network can be at risk if the patch is not applied.

Generated by OpenCVE AI on August 4, 2026 at 16:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch released by Oracle as detailed in the CPU Jul 2026 advisory.
  • Restrict network access to the Oracle General Ledger SOAP service to trusted hosts.
  • Disable or secure the SOAP interface on non‑production instances if not required.
  • Monitor logs for anomalous SOAP activity.
  • Enforce strict audit trails for sensitive operations.

Generated by OpenCVE AI on August 4, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege SOAP Exploit Enables Takeover of Oracle General Ledger

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege SOAP Exploit Enables Takeover of Oracle General Ledger

Sun, 26 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low Privilege SOAP Remote Exploit in Oracle General Ledger
Weaknesses CWE-284

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low Privilege SOAP Remote Exploit in Oracle General Ledger
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in takeover of Oracle General Ledger. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle general Ledger
CPEs cpe:2.3:a:oracle:general_ledger:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle general Ledger
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle E-business Suite General Ledger
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:18:44.898Z

Reserved: 2026-07-08T15:51:55.577Z

Link: CVE-2026-60678

cve-icon Vulnrichment

Updated: 2026-07-24T19:18:41.166Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:08.793

Modified: 2026-08-07T21:19:08.590

Link: CVE-2026-60678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function