Description
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Asset Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Enterprise Asset Management (part of Oracle E‑Business Suite) has a flaw in its Internal Operations component that permits an attacker who already has high‑level privileges and network connectivity over HTTP to compromise the application. The issue is an access‑control problem, identified as CWE‑284, allowing the attacker to bypass intended authorization controls and create, delete, or modify critical data, as well as read all data stored in the application. The CVSS 3.1 vector indicates confidentiality and integrity impact metrics without an availability impact, reflecting the destructive potential of the vulnerability on data integrity and confidentiality.

Affected Systems

The affected vendor is Oracle Corporation and the product is Oracle Enterprise Asset Management. Versions 12.2.3 through 12.2.15 are affected. The flaw exists in the internal operations component of this product.

Risk and Exploitability

The CVSS 3.1 Base Score of 5.9 denotes moderate severity, with confidentiality and integrity impact metrics. The EPSS score of less than 1 % indicates a very low probability of exploitation at the time of this analysis. The vulnerability is not recorded in the CISA KEV catalog. The likely attack vector is over the internal network via HTTP and requires that the attacker already possess high privileges within the environment, so exploitation is limited to internal or privileged threat actors.

Generated by OpenCVE AI on August 2, 2026 at 21:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 update that addresses CVE‑2026‑60695 to all affected Oracle Enterprise Asset Management installations.
  • Restrict HTTP access to the Oracle Enterprise Asset Management application by configuring firewall rules so that only trusted internal hosts can reach the service.
  • Review and enforce least‑privilege access controls for internal operations users to prevent unauthorized data modifications.

Generated by OpenCVE AI on August 2, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability in Oracle Enterprise Asset Management Enables Privileged Attacker to Modify Data Over HTTP

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title High‑Privilege Data Modification via HTTP in Oracle Enterprise Asset Management

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title High‑Privilege Data Modification via HTTP in Oracle Enterprise Asset Management

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Asset Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle enterprise Asset Management
CPEs cpe:2.3:a:oracle:enterprise_asset_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Asset Management
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Enterprise Asset Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:25:00.502Z

Reserved: 2026-07-08T15:51:55.579Z

Link: CVE-2026-60695

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:50.965Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:10.260

Modified: 2026-07-28T17:20:03.460

Link: CVE-2026-60695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses