Description
Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Intelligence accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle E‑Business Intelligence allows a low‑privileged attacker who can reach the system over HTTP to bypass normal access controls and create, delete, or modify critical data, giving the attacker full control over the information exposed by the product. The CVSS 3.1 base score of 8.1 reflects substantial confidentiality and integrity impacts without affecting availability.

Affected Systems

Affected vendors and products include Oracle Corporation’s Oracle E‑Business Intelligence component of the Oracle E‑Business Suite. The problematic versions range from 12.2.3 through 12.2.15. No other versions or components are listed as affected.

Risk and Exploitability

The EPSS score of less than 1% indicates that while the vulnerability exists, the likelihood of exploitation is currently low, and the vulnerability is not included in the CISA KEV catalog. However, the attack vector is inferred to be network‑based over unsecured HTTP, requiring only low privileges, which makes it potentially exploitable in environments that expose this interface to the internet or to untrusted networks. The combination of a high CVSS score and an easily exploitable attack surface places high risk on systems lacking the latest patch.

Generated by OpenCVE AI on August 4, 2026 at 02:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle E‑Business Intelligence to a patched version 12.2.16 or later
  • Restrict external HTTP access to the E‑Business Intelligence endpoints and limit it to trusted internal networks
  • Implement strict role‑based access controls and enable audit logging to detect and deter unauthorized data changes

Generated by OpenCVE AI on August 4, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP‑Based Data Modification in Oracle E‑Business Intelligence

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP‑Based Data Modification in Oracle E‑Business Intelligence

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privileged HTTP Access in Oracle E‑Business Intelligence

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privileged HTTP Access in Oracle E‑Business Intelligence
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Definition). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Intelligence accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle e-business Intelligence
CPEs cpe:2.3:a:oracle:e-business_intelligence:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle e-business Intelligence
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle E-business Intelligence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:23:28.218Z

Reserved: 2026-07-08T15:51:55.585Z

Link: CVE-2026-60736

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:36.391Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses