Description
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Asset Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Enterprise Asset Management suffers an authorization flaw that allows an attacker with low privileges and network access via HTTP to update, insert, or delete data and read restricted information, provided a human actor other than the attacker participates in the process. The flaw provides both confidentiality and integrity impact, enabling unauthorized manipulation of Asset Management data.

Affected Systems

The affected vendor is Oracle Corporation. The product is Oracle Enterprise Asset Management, part of the Oracle E‑Business Suite, specifically the Internal Operations component. Versions from 12.2.3 through 12.2.15 are vulnerable.

Risk and Exploitability

The vulnerability carries a 5.4 CVSS‑3.1 score and an EPSS score of less than 1 %. It is not listed in the CISA KEV catalog. The attack requires HTTP network connectivity and low privileged credentials, and the attack vector involves probable human interaction. The scope change indicates that successful exploitation could affect additional Oracle products beyond Enterprise Asset Management.

Generated by OpenCVE AI on August 4, 2026 at 03:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for CVE-2026-60694 as soon as it is available.
  • Limit HTTP access to the Enterprise Asset Management instance to trusted IP ranges and enforce strong authentication.
  • Review and reduce the privileges of users with low-level access, ensuring they cannot perform update, insert, or delete operations on critical data.

Generated by OpenCVE AI on August 4, 2026 at 03:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via Low-Privilege HTTP Interaction in Oracle Enterprise Asset Management

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP-Based Unauthorized Data Modification in Oracle Enterprise Asset Management
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP-Based Unauthorized Data Modification in Oracle Enterprise Asset Management
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Asset Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle enterprise Asset Management
CPEs cpe:2.3:a:oracle:enterprise_asset_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Asset Management
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Enterprise Asset Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:25:09.543Z

Reserved: 2026-07-08T15:51:55.579Z

Link: CVE-2026-60694

cve-icon Vulnrichment

Updated: 2026-07-24T15:15:24.137Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:10.150

Modified: 2026-07-28T17:19:53.220

Link: CVE-2026-60694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses