Description
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iSupport accessible data as well as unauthorized read access to a subset of Oracle iSupport accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle iSupport of Oracle E‑Business Suite lets an unauthenticated attacker with network access via HTTP potentially compromise the application. The functionality requires the attacker to rely on an outside human user to trigger the exploitation, but once active it can grant unauthorized insert, update or delete rights on data accessible through iSupport as well as read access to a subset of that data. The weakness involves misconfigured access controls (CWE‑284) coupled with cross‑site request forgery (CWE‑352) and unreliable redirect handling (CWE‑601).

Affected Systems

The vulnerability affects Oracle iSupport for Oracle E‑Business Suite, impacting all installed versions from 12.2.3 up through 12.2.15. These versions support the Internal Operations component and are reachable over standard HTTP ports.

Risk and Exploitability

The CVSS v3.1 base score of 6.1 indicates moderate confidentiality and integrity impact. The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low current exploitation probability. However, the need for a human interaction to complete the attack does not eliminate risk, and the potential for data tampering and disclosure warrants timely remediation.

Generated by OpenCVE AI on August 4, 2026 at 03:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor patch or security update that addresses the flaw in Oracle iSupport versions 12.2.3–12.2.15.
  • Restrict HTTP traffic to the iSupport application by permitting only trusted internal IP addresses and blocking external access.
  • Enforce least‑privilege on iSupport user accounts, disabling any remote features or permissions that are not required for normal operation.

Generated by OpenCVE AI on August 4, 2026 at 03:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based data modification and disclosure in Oracle iSupport

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Modification and Disclosure in Oracle iSupport

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Modification and Disclosure in Oracle iSupport
Weaknesses CWE-285

Sun, 26 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated HTTP Access in Oracle iSupport

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated HTTP Access in Oracle iSupport
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iSupport accessible data as well as unauthorized read access to a subset of Oracle iSupport accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle isupport
CPEs cpe:2.3:a:oracle:isupport:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isupport
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle E-business Suite Isupport
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:12:22.142Z

Reserved: 2026-07-08T15:51:55.578Z

Link: CVE-2026-60685

cve-icon Vulnrichment

Updated: 2026-07-24T19:12:17.623Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:09.240

Modified: 2026-08-07T21:11:15.770

Link: CVE-2026-60685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')