Description
Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle U.S. Federal Financials. While the vulnerability is in Oracle U.S. Federal Financials, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle U.S. Federal Financials accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the internal operations component of Oracle U.S. Federal Financials and allows unauthenticated attackers with HTTPS network access to bypass missing authentication, granting read‑only access to all confidential data available through the application. The flaw involves improper authentication (CWE‑284) and a confidentiality issue (CWE‑200), and does not affect integrity or availability.

Affected Systems

Oracle U.S. Federal Financials, part of Oracle E‑Business Suite, from version 12.2.3 through 12.2.15, is affected; the internal operations component is exposed via HTTPS. Although the primary target is this product, the vulnerability’s scope may extend to other Oracle products linked or accessed through the same service.

Risk and Exploitability

The CVSS 3.1 base score of 6.8 indicates medium severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers with network access to the affected HTTPS interface can attempt to use the identified authentication bypass; if successful, the attacker would obtain read‑only access to all data the application can return, effectively compromising confidential information.

Generated by OpenCVE AI on August 2, 2026 at 21:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that resolves CVE‑2026‑60687 without delay
  • Restrict HTTPS access to Oracle U.S. Federal Financials to known, trusted IP addresses or VPNs to limit network exposure
  • Implement continuous monitoring for failed authentication attempts and abnormal data read patterns to detect potential exploitation

Generated by OpenCVE AI on August 2, 2026 at 21:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Access Allows Confidential Data Exposure in Oracle U.S. Federal Financials

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Exploit in Oracle U.S. Federal Financials
Weaknesses CWE-269
CWE-285

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Exploit in Oracle U.S. Federal Financials
Weaknesses CWE-269
CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle U.S. Federal Financials. While the vulnerability is in Oracle U.S. Federal Financials, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle U.S. Federal Financials accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle u.s. Federal Financials
CPEs cpe:2.3:a:oracle:u.s._federal_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle u.s. Federal Financials
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle U.s. Federal Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:10:44.666Z

Reserved: 2026-07-08T15:51:55.578Z

Link: CVE-2026-60687

cve-icon Vulnrichment

Updated: 2026-07-24T19:10:39.209Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control