Description
Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cash Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cash Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cash Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Cash Management product in Oracle E‑Business Suite contains an easily exploitable flaw that permits a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data and to gain unauthorized access to all data that the application can access. This improper access control on internal operations allows actions that are normally restricted to higher privileged users, thereby compromising the confidentiality and integrity of the financial data used by the system.

Affected Systems

Oracle Cash Management versions 12.2.3 through 12.2.15 are affected. These versions are deployed within Oracle E‑Business Suite environments where internal operations are enabled, meaning that any instance running those versions without the latest patch is vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates high severity with high confidentiality and integrity impacts. The EPSS score is less than 1%, suggesting that exploitation has not yet been widely observed, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is straightforward—remote, unmediated access via HTTP—and requires only low pre‑existing privileges, making it an attractive target for attackers who can reach the affected services.

Generated by OpenCVE AI on August 2, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Cash Management to version 12.2.16 or later as recommended in the Oracle CPU Jul 2026 advisory.
  • If an immediate upgrade is not possible, disable the vulnerable internal operations functionality or enforce stricter role‑based access controls to limit low‑privileged users’ permissions.
  • Apply the patch or update detailed in the official Oracle security announcement (https://www.oracle.com/security-alerts/cpujul2026.html).

Generated by OpenCVE AI on August 2, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Data Modification Vulnerability in Oracle Cash Management

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Data Modification and Unauthorized Access in Oracle Cash Management
Weaknesses CWE‑284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote Data Modification and Unauthorized Access in Oracle Cash Management
Weaknesses CWE‑284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Cash Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cash Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cash Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cash Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle cash Management
CPEs cpe:2.3:a:oracle:cash_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle cash Management
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Cash Management E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:23:04.556Z

Reserved: 2026-07-08T15:51:55.585Z

Link: CVE-2026-60740

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:33.526Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:14.460

Modified: 2026-08-06T15:07:18.387

Link: CVE-2026-60740

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses