Description
Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iReceivables accessible data as well as unauthorized access to critical data or complete access to all Oracle iReceivables accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle iReceivables product contains an easily exploitable flaw in the AR Web Utilities that allows a low privileged attacker who can reach the server via HTTP to create, delete, or modify critical data. Successful exploitation leads to confidentiality and integrity breaches, allowing unauthorized or complete access to all iReceivables data.

Affected Systems

Oracle iReceivables versions from 12.2.3 through 12.2.15 are impacted. The affected component is the AR Web Utilities of the Oracle E‑Business Suite.

Risk and Exploitability

The CVSS base score of 8.1 indicates high severity with both confidentiality and integrity impacts. The EPSS score of less than 1% shows a very low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based over HTTP, requiring only low privileges to achieve significant data disruption.

Generated by OpenCVE AI on August 4, 2026 at 02:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle iReceivables to version 12.2.16 or later, or apply the 2026 July CPU patch that contains the fix.
  • Configure network controls to limit HTTP access to trusted IP addresses and require VPN or SSH tunneling for management traffic.
  • Implement logging and auditing of DML operations on critical data and review logs for unauthorized creation or deletion attempts.

Generated by OpenCVE AI on August 4, 2026 at 02:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Data Modification and Access via HTTP in Oracle iReceivables

Mon, 27 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Web Utilities in Oracle iReceivables

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Web Utilities in Oracle iReceivables
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iReceivables accessible data as well as unauthorized access to critical data or complete access to all Oracle iReceivables accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle ireceivables
CPEs cpe:2.3:a:oracle:ireceivables:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle ireceivables
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Ireceivables
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:23:53.154Z

Reserved: 2026-07-08T15:51:55.584Z

Link: CVE-2026-60732

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:40.992Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:13.587

Modified: 2026-07-30T17:35:53.220

Link: CVE-2026-60732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses