Description
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle General Ledger. While the vulnerability is in Oracle General Ledger, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data as well as unauthorized update, insert or delete access to some of Oracle General Ledger accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle General Ledger is vulnerable to a high‑privilege attack that can be carried out over HTTP. The flaw allows an attacker who can reach the system on the network to gain unauthorized read access to sensitive data as well as insert, update, or delete operations on ledger records. The vulnerability is categorized as a privilege escalation and unauthorized data modification attack, leading to potential loss of confidentiality and integrity for all data accessible through Oracle General Ledger.

Affected Systems

Oracle General Ledger, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The flaw exists in the Internal Operations component and may also impact other products within the suite due to a scope escalation.

Risk and Exploitability

The CVSS v3.1 base score of 7.6 indicates significant potential impact. The EPSS score of <1% (about 0.003) indicates a very low but non‑zero probability of exploitation; this suggests the flaw is not widely observed but could still be targeted. The vulnerability is easily exploitable over the network via HTTP. It is not currently listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is inferred to be remote over the network, requiring high privileges and no user interaction, which suggests that an attacker with network access can exploit the flaw directly.

Generated by OpenCVE AI on August 21, 2026 at 16:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a non‑affected version as detailed in Oracle’s security alert
  • Limit HTTP access to the Oracle General Ledger component to trusted networks or VPN segments only
  • Enforce strict privilege controls and monitor for anomalous ledger modifications

Generated by OpenCVE AI on August 21, 2026 at 16:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Network‑Based High Privilege Exploitation of Oracle General Ledger Allows Unauthorized Access and Data Modification

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle General Ledger. While the vulnerability is in Oracle General Ledger, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data as well as unauthorized update, insert or delete access to some of Oracle General Ledger accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle general Ledger
CPEs cpe:2.3:a:oracle:general_ledger:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle general Ledger
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle General Ledger
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:17:13.127Z

Reserved: 2026-07-08T15:51:55.587Z

Link: CVE-2026-60748

cve-icon Vulnrichment

Updated: 2026-08-20T19:17:07.824Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:41.567

Modified: 2026-08-25T17:48:47.560

Link: CVE-2026-60748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:45:03Z

Weaknesses