Description
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Oracle Cost Management vulnerability allows a low‑privileged attacker with network access via HTTP to gain unauthorized control over critical data, enabling creation, deletion, or modification of records. The flaw can thus lead to significant compromise of confidentiality and integrity of all Oracle Cost Management accessible data, without affecting availability.

Affected Systems

Oracle Cost Management (part of Oracle E‑Business Suite) versions 12.2.3 through 12.2.15 are affected. All installations using these versions are vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, but the EPSS score of less than 1% shows a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only low‑privilege access to the HTTP interface, which is typically reachable over the network. Once accessed, an attacker can authenticate with minimal privileges and exercise full data‑manipulation rights due to the underlying access‑control weakness.

Generated by OpenCVE AI on August 4, 2026 at 16:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest available Oracle patch for Cost Management 12.2.3-12.2.15.
  • Restrict HTTP access to the Cost Management component to trusted networks only, or place a firewall rule to block unauthorised IP ranges.
  • Implement role‑based access controls and regularly audit logs to detect unauthorized data changes and enforce least privilege.

Generated by OpenCVE AI on August 4, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Access Enables Unauthorized Data Manipulation in Oracle Cost Management

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Access Enables Unauthorized Data Manipulation in Oracle Cost Management

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title High-Severity Unauthorized Data Modification in Oracle Cost Management

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title High-Severity Unauthorized Data Modification in Oracle Cost Management
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle cost Management
CPEs cpe:2.3:a:oracle:cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle cost Management
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Cost Management E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:01:04.714Z

Reserved: 2026-07-08T15:51:55.586Z

Link: CVE-2026-60741

cve-icon Vulnrichment

Updated: 2026-07-24T19:01:00.300Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:14.577

Modified: 2026-07-29T15:52:49.547

Link: CVE-2026-60741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses