Description
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Internal Operations component of Oracle Cost Management and permits a low‑privileged attacker with network access over HTTP to compromise the application. An attacker can create, delete, or modify data and gain full access to all data that the application exposes. The impact is significant confidentiality and integrity loss, while availability is not directly affected. The weakness aligns with improper access control and input validation issues, as the application fails to restrict unauthorized operations to privileged users.

Affected Systems

Oracle Cost Management for Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are installed in many enterprise environments where the application is accessed via web interfaces. Users of these products must verify their deployed version against the listed range.

Risk and Exploitability

The CVSS 3.1 score of 6.8 indicates a moderate severity with high confidentiality and integrity impact. The EPSS score of less than 1 % reveals that exploitation is currently considered unlikely, and the vulnerability is not listed in CISA’s KEV catalog. However, because an attacker only needs low privileges and network reachability to HTTP, the attack vector is convenient for internal threat actors or compromised accounts. Successful exploitation can lead to unauthorized data changes or disclosure of all applications data, compromising regulatory compliance and audit controls.

Generated by OpenCVE AI on August 2, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Business Suite patches that address CVE-2026-60744 as soon as they are released
  • Restrict inbound HTTP traffic to Oracle Cost Management endpoints to trusted IP ranges or VPNs to limit exposure to low‑privileged users
  • Enable comprehensive logging and audit trails for all data modification review logs for suspicious activity

Generated by OpenCVE AI on August 2, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Access in Oracle Cost Management via HTTP

Mon, 27 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Access in Oracle Cost Management via HTTP

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle cost Management
CPEs cpe:2.3:a:oracle:cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle cost Management
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Cost Management E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:00:13.347Z

Reserved: 2026-07-08T15:51:55.586Z

Link: CVE-2026-60744

cve-icon Vulnrichment

Updated: 2026-07-24T19:00:07.899Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:14.690

Modified: 2026-07-28T21:03:23.257

Link: CVE-2026-60744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses