Description
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Applications Framework contains a flaw in the Upload Attachments component that enables a low‑privileged attacker with network access via HTTP to perform unauthorized update, insert, delete, or read operations on data exposed by the framework. The vulnerability—rated CVSS 3.1 with a base score of 4.6—reflects modest confidentiality and integrity impacts and requires human interaction from a user distinct from the attacker. An attacker can exploit the flaw only after a user has interacted with the application, making the attack window narrower but still viable for targeted campaigns. This flaw is a manifestation of CWE‑284, which indicates an unauthorized access weakness.

Affected Systems

The flaw affects Oracle E‑Business Suite Versions 12.2.8 through 12.2.15. All instances of Oracle Applications Framework within these releases are potentially vulnerable and should be identified in the environment.

Risk and Exploitability

With an EPSS score of less than 1% and no listing in the CISA KEV catalog, the likelihood of widespread exploitation is low, yet the potential for data integrity loss exists. The attack vector is likely network‑based, leveraging HTTP requests to the Upload Attachments endpoint, and requires the victim to initiate or complete a user interaction step. The moderate CVSS score reflects that the flaw does not allow full compromise but can lead to unauthorized data manipulation while keeping the attacker’s presence relatively covert. The CVSS base score is 4.6.

Generated by OpenCVE AI on August 2, 2026 at 21:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s support portal for security advisories and apply any available patch or update that addresses the upload attachments vulnerability
  • Disable or restrict the upload attachments feature to trusted users or remove it entirely if not needed
  • Configure network segmentation or firewall rules to limit HTTP access to the Applications Framework only from trusted IP ranges

Generated by OpenCVE AI on August 2, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Upload Attachments in Oracle Applications Framework

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Unauthorized Data Manipulation via Oracle Applications Framework Upload Attachments

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Unauthorized Data Manipulation via Oracle Applications Framework Upload Attachments
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle applications Framework
CPEs cpe:2.3:a:oracle:applications_framework:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Framework
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Applications Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:13:07.259Z

Reserved: 2026-07-08T15:51:55.578Z

Link: CVE-2026-60684

cve-icon Vulnrichment

Updated: 2026-07-24T19:13:02.248Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:09.130

Modified: 2026-07-31T21:23:42.813

Link: CVE-2026-60684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses