Description
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data as well as unauthorized read access to a subset of Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Customer Interaction History product in Oracle E‑Business Suite contains a flaw in the Outcome‑Result component that permits a low‑privileged attacker with HTTP network access to perform unauthorized update, insert, delete, or read operations on accessible data. This flaw can compromise the confidentiality and integrity of customer interaction records, allowing an attacker to alter records or expose sensitive information. The vulnerability is identified as a low‑privileged access control bypass and results in a CVSS 3.1 base score of 5.4, with confidentiality and integrity impacts rated low.

Affected Systems

The affected versions are Oracle Customer Interaction History 12.2.3 through 12.2.15 in the Oracle E‑Business Suite. Any installation of these releases that has the Outcome‑Result component exposed over HTTP is potentially vulnerable. No other product or version is listed as affected.

Risk and Exploitability

The risk assessment shows a moderate severity CVSS score of 5.4 and an EPSS score of less than 1%, indicating that attempted exploitation is unlikely at this time. The vulnerability is currently not listed in CISA’s KEV catalog. The attack vector is a network interaction over HTTP and the requirement is a low‑privileged account within the Oracle E‑Business Suite. Because the flaw allows data modification and disclosure, it is advisable to apply mitigations promptly.

Generated by OpenCVE AI on August 4, 2026 at 02:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the July 2026 Oracle E‑Business Suite update that addresses the Oracle Customer Interaction History vulnerability (see the Oracle security alert for CVE‑2026‑60724).
  • Restrict HTTP access to the Oracle Customer Interaction History component to internal networks or VPN only and block public ingress.
  • Enforce strict role‑based permissions so that low‑privileged users have no write access to Outcome‑Result data, and enable audit logging for all create, update, and delete operations.

Generated by OpenCVE AI on August 4, 2026 at 02:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Bypass Allowing Unauthorized Data Modification and Disclosure in Oracle Customer Interaction History

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Bypass Allowing Unauthorized Data Modification and Disclosure in Oracle Customer Interaction History

Mon, 27 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Modification in Oracle Customer Interaction History via HTTP

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Modification in Oracle Customer Interaction History via HTTP

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data as well as unauthorized read access to a subset of Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle customer Interaction History
CPEs cpe:2.3:a:oracle:customer_interaction_history:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle customer Interaction History
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Customer Interaction History
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:24:16.253Z

Reserved: 2026-07-08T15:51:55.583Z

Link: CVE-2026-60724

cve-icon Vulnrichment

Updated: 2026-07-24T15:15:20.557Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:12.490

Modified: 2026-07-24T16:16:38.590

Link: CVE-2026-60724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses