Description
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in takeover of Oracle Installed Base. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Installed Base component of Oracle E‑Business Suite allows a low‑privileged attacker with network access via HTTP to acquire full control of the system. Successful exploitation results in complete takeover, compromising confidentiality, integrity and availability of the installed product.

Affected Systems

Oracle E‑Business Suite Oracle Installed Base versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The issue carries a CVSS 3.1 score of 8.8, indicating high severity. The EPSS score is <1%, suggesting exploitation is currently unlikely but not impossible. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attacker must have network access to the HTTP interface; no special user privileges beyond low are required to launch the attack.

Generated by OpenCVE AI on August 4, 2026 at 02:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Oracle Installed Base that addresses this vulnerability
  • Mitigate the authorization weakness (CWE-284) by limiting HTTP access to the Installed Base for trusted networks only
  • Ensure the deployed version is outside the affected range (12.2.3‑12.2.15)
  • Block non‑essential inbound traffic to the Installed Base via firewall or network segmentation

Generated by OpenCVE AI on August 4, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Oracle Installed Base: Low-Privilege HTTP Remote Takeover

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote HTTP Endpoint Exploit Enables Full Control of Oracle Installed Base
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote HTTP Endpoint Exploit Enables Full Control of Oracle Installed Base
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in takeover of Oracle Installed Base. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle installed Base
CPEs cpe:2.3:a:oracle:installed_base:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle installed Base
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Installed Base
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:23:21.241Z

Reserved: 2026-07-08T15:51:55.585Z

Link: CVE-2026-60738

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:35.144Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:14.227

Modified: 2026-07-30T17:36:03.477

Link: CVE-2026-60738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses