Description
Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Assets accessible data as well as unauthorized access to critical data or complete access to all Oracle Assets accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Assets, part of Oracle E‑Business Suite’s Internal Operations component, permits an attacker with low privileges and network access over HTTP to gain unauthorized capabilities. The vulnerability enables the attacker to delete, modify, or read critical data or all data accessible to Oracle Assets, causing loss of confidentiality and integrity of the asset information.

Affected Systems

Oracle Corporation’s Oracle Assets product for Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15, is impacted.

Risk and Exploitability

The CVSS 3.1 score of 8.1 indicates a serious security risk, while the low EPSS score (<1%) suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attack would likely be performed over a public or internal network via standard HTTP requests, exploiting insufficient privilege checks in the Internal Operations interface.

Generated by OpenCVE AI on August 2, 2026 at 21:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Assets patch as soon as it is released by Oracle Corporation.
  • Restrict HTTP access to Oracle Assets by configuring firewalls or network segmentation so that only trusted hosts can reach the service.
  • Enable strict authentication and authorization controls, ensuring that only authorized users can perform create, delete, and modify operations within Oracle Assets.

Generated by OpenCVE AI on August 2, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Unauthorized Data Manipulation in Oracle Assets

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Unauthorized Data Manipulation in Oracle Assets

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Asset Management Access in Oracle Assets 12.2.x

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Asset Management Access in Oracle Assets 12.2.x

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Assets accessible data as well as unauthorized access to critical data or complete access to all Oracle Assets accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle assets
CPEs cpe:2.3:a:oracle:assets:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle assets
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Assets E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:02:41.692Z

Reserved: 2026-07-08T15:51:55.587Z

Link: CVE-2026-60749

cve-icon Vulnrichment

Updated: 2026-07-24T19:02:36.420Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:14.917

Modified: 2026-08-06T15:07:38.167

Link: CVE-2026-60749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses