Description
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair and Overhaul accessible data as well as unauthorized read access to a subset of Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in the Common Utilities component of Oracle Complex Maintenance, Repair and Overhaul allows a low‑privileged attacker with network access via HTTP to gain unauthorized update, insert, delete and read access to Oracle data. The weakness is a flaw in access control (CWE‑284), resulting in moderate confidentiality and integrity impacts reflected by the CVSS base score of 5.4.

Affected Systems

Affected systems are Oracle E‑Business Suite’s Oracle Complex Maintenance, Repair and Overhaul product, version range 12.2.3 to 12.2.15. The Common Utilities component is the entry point for the vulnerability and is accessible over HTTP.

Risk and Exploitability

The CVSS base score of 5.4 indicates moderate severity, and the EPSS score of <1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. Exploitation requires only network connectivity to the HTTP interface and low privileges, so the likely attack vector—based on the description—is limited to internal or compromised network segments.

Generated by OpenCVE AI on August 5, 2026 at 01:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle website for any available updates or patches for Oracle Complex Maintenance, Repair and Overhaul 12.2.3-12.2.15.
  • Limit HTTP access to the OEM server to trusted hosts using firewall rules or VPNs.
  • Monitor database logs for unexpected update, insert, delete, or read operations on OEM data.

Generated by OpenCVE AI on August 5, 2026 at 01:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Complex Maintenance, Repair and Overhaul

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Complex Maintenance, Repair and Overhaul

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Attack Allows Unauthorized Data Modification in Oracle Complex Maintenance, Repair and Overhaul

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Attack Allows Unauthorized Data Modification in Oracle Complex Maintenance, Repair and Overhaul
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair and Overhaul accessible data as well as unauthorized read access to a subset of Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle complex Maintenance Repair And Overhaul
CPEs cpe:2.3:a:oracle:complex_maintenance__repair_and_overhaul:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle complex Maintenance Repair And Overhaul
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Complex Maintenance Repair And Overhaul Complex Maintenance Repair And Overhaul
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:07:34.944Z

Reserved: 2026-07-08T15:51:55.582Z

Link: CVE-2026-60717

cve-icon Vulnrichment

Updated: 2026-07-24T19:07:31.521Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:12.020

Modified: 2026-08-03T16:53:08.130

Link: CVE-2026-60717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses