Description
Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Content Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Content Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Content Manager in Oracle E‑Business Suite is vulnerable to a low‑privilege attacker over HTTP via an improper access control flaw (CWE‑284). The flaw permits unauthorized creation, deletion, or modification of content and can grant full access to all data exposed by the application, compromising confidentiality and integrity. The vulnerability is classified as a high‑severity issue with a CVSS 3.1 score of 8.1, reflecting strong potential impact on data security.

Affected Systems

Oracle Content Manager, versions 12.2.3 through 12.2.15, within the Oracle E‑Business Suite, are affected. The vulnerability impacts all deployments of these versions that are reachable over HTTP.

Risk and Exploitability

The CVSS score of 8.1 indicates a high level of risk. The EPSS value is below 1%, suggesting that automated exploitation is currently rare, though manual exploitation is still feasible. The issue is not currently listed in the CISA KEV catalog, which may reflect a lower observed exploitation rate. Attackers require only low network privileges and need HTTP access to the vulnerable instance, making the threat vector straightforward for attackers who can reach the application over the network.

Generated by OpenCVE AI on August 5, 2026 at 01:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any Oracle Content Manager security update that addresses this flaw.
  • Restrict network access to the Oracle Content Manager service, allowing only trusted internal networks or VPN connections, thereby reducing exposure to unauthenticated users.
  • Enable comprehensive logging and audit trails for the Content Manager, and monitor for anomalous activities such as unexpected creation or deletion of content, to detect and respond to potential exploitation attempts.

Generated by OpenCVE AI on August 5, 2026 at 01:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Allows Unauthorized Data Manipulation in Oracle Content Manager

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Allows Unauthorized Data Manipulation in Oracle Content Manager

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low Privilege Access to Oracle Content Manager via HTTP Allows Unauthorized Data Manipulation

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Access to Oracle Content Manager via HTTP Allows Unauthorized Data Manipulation
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Content Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Content Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Content Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle content Manager
CPEs cpe:2.3:a:oracle:content_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle content Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Content Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:25:25.148Z

Reserved: 2026-07-08T15:51:55.578Z

Link: CVE-2026-60691

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:54.607Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:09.923

Modified: 2026-08-06T15:29:34.033

Link: CVE-2026-60691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses