Description
Vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (component: Rules UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scheduler. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Scheduler accessible data as well as unauthorized read access to a subset of Oracle Scheduler accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scheduler. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the Oracle Scheduler Rules UI component that can be exploited by an attacker who has a low‑privilege account and network connectivity over HTTP. The weakness allows unauthorized updates, inserts, deletions and restricted reads of Scheduler data, and can also trigger a partial denial of service. These capabilities affect confidentiality, integrity, and availability, and stem from improper enforcement of access control requirements.

Affected Systems

Oracle Scheduler, part of Oracle E‑Business Suite, is impacted for versions 12.2.3 through 12.2.15. The vulnerability is confined to the Rules UI feature of Scheduler, which is reachable via standard web requests.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, while an EPSS score of less than 1% signals a low probability of exploitation today. The vulnerability is not listed in the CISA KEV catalog. Attackers can leverage standard HTTP traffic to the Scheduler service; no elevated credentials, privileged permissions, or remote code execution are required. Successful exploitation results in unauthorized data modification, limited read access, and a partial availability impact.

Generated by OpenCVE AI on August 4, 2026 at 03:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Scheduler patch released in Oracle Security Alert CPU Jul 2026 for all affected 12.2.x versions.
  • Limit external HTTP access to the Scheduler service by firewalling or VPN gating to trusted networks.
  • Enforce stricter role‑based access controls for the Rules UI and monitor logs for anomalous write or read activity, alerting on repeated unauthorized attempts.

Generated by OpenCVE AI on August 4, 2026 at 03:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification in Oracle Scheduler Rules UI

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification in Oracle Scheduler Rules UI

Mon, 27 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Modification and Partial Denial of Service in Oracle Scheduler Rules UI
Weaknesses CWE-269

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Modification and Partial Denial of Service in Oracle Scheduler Rules UI
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (component: Rules UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scheduler. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Scheduler accessible data as well as unauthorized read access to a subset of Oracle Scheduler accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scheduler. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle scheduler
CPEs cpe:2.3:a:oracle:scheduler:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle scheduler
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle E-business Suite Scheduler
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:11:33.952Z

Reserved: 2026-07-08T15:51:55.578Z

Link: CVE-2026-60688

cve-icon Vulnrichment

Updated: 2026-07-24T19:11:30.335Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:09.587

Modified: 2026-08-06T14:59:20.680

Link: CVE-2026-60688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses