Description
Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Site Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Site Hub accessible data as well as unauthorized read access to a subset of Oracle Site Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Site Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in Oracle Site Hub’s Site Hierarchy Flows component and is caused by an insufficient access‑control check (CWE‑284). An attacker with low system privileges who can reach the web interface via HTTP can create, read, update, or delete data that should be protected. Successful exploitation can alter or delete confidential content, expose sensitive records, and trigger a temporary denial of service that disrupts Hub availability.

Affected Systems

Affected products are Oracle Site Hub, part of Oracle E‑Business Suite, for releases 12.2.3 through 12.2.15. These versions contain the unpatched Site Hierarchy Flows code that permits the described operations. Higher‑level releases are not listed as vulnerable by Oracle.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. An EPSS score of < 1 % suggests a very low likelihood of active exploitation at present, and the issue is not in the CISA KEV catalog. Nevertheless, the vulnerability can be reached over the network via HTTP without special setup, so a compromised network segment could use this flaw to alter data or interrupt service. The risk to data integrity and business continuity remains significant.

Generated by OpenCVE AI on August 4, 2026 at 03:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle Site Hub patch that fixes the Site Hierarchy Flows vulnerability to all affected 12.2.3‑12.2.15 installations.
  • Immediately block low‑privilege users from performing CRUD actions on the Site Hierarchy Flows feature by tightening role‑based access controls and removing default permissions.
  • Continuously audit Site Hub logs for unauthorized create, read, update, delete activity and configure alerts to detect suspicious operations.
  • If the patch cannot be applied immediately, restrict the Site Hierarchy Flows HTTP endpoint to a known, trusted IP range or disable the feature until a fix is available.

Generated by OpenCVE AI on August 4, 2026 at 03:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Oracle Site Hub Unauthorized Data Modification via Low-Privilege HTTP Access

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Oracle Site Hub Unauthorized Data Modification via Low-Privilege HTTP Access

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in Oracle Site Hub

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in Oracle Site Hub
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Site Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Site Hub accessible data as well as unauthorized read access to a subset of Oracle Site Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Site Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle site Hub
CPEs cpe:2.3:a:oracle:site_hub:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle site Hub
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle E-business Suite Site Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:24:53.789Z

Reserved: 2026-07-08T15:51:55.579Z

Link: CVE-2026-60697

cve-icon Vulnrichment

Updated: 2026-07-24T15:15:22.270Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:10.373

Modified: 2026-08-06T14:59:34.243

Link: CVE-2026-60697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses