Description
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle General Ledger. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-08-18
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Internal Operations component of Oracle General Ledger allows a low‑privileged attacker who can access the system over HTTP to create, delete, or modify critical data, gain full data access, or cause a partial denial of service. The flaw is an access control weakness that permits unauthorized operations, leading to confidentiality, integrity, and availability impacts as reflected in the CVSS vector. Successful exploitation means the attacker can tamper with ledger entries, obscure audit trails, or disrupt processing for affected users.

Affected Systems

All installations of Oracle Corporation’s Oracle General Ledger Product, versions 12.2.3 through 12.2.15, are affected. The vulnerability resides in the Internal Operations component and is reachable via HTTP. Oracle E‑Business Suite deployments that include these versions should be reviewed for this flaw.

Risk and Exploitability

The CVSS Base Score of 7.1 indicates high severity with a Network attack vector, High attack complexity, Low Privileges, no User Interaction, and a Unchanged scope. Although the EPSS score is not available, the score and vector suggest that exploitation is technically feasible with minimal effort from a network‑level attacker. As of now the vulnerability is not listed in CISA’s KEV catalog, implying no confirmed field‑used exploits, but the lack of protection mechanisms and the high impact warrant prompt attention.

Generated by OpenCVE AI on August 18, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch released in the Oracle security alert for CVE-2026-60693
  • Restrict HTTP access to the Internal Operations component of Oracle General Ledger to trusted networks or authenticated users
  • Configure role‑based access controls so that only privileged users can create, delete, or modify General Ledger data
  • Enable logging and monitoring for unauthorized access attempts to the affected component

Generated by OpenCVE AI on August 18, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Allows Unauthorized Data Manipulation in Oracle General Ledger
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle General Ledger. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle general Ledger
CPEs cpe:2.3:a:oracle:general_ledger:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle general Ledger
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle General Ledger
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:58.206Z

Reserved: 2026-07-08T15:51:55.579Z

Link: CVE-2026-60693

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:39.197

Modified: 2026-08-18T21:16:39.197

Link: CVE-2026-60693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses