Description
Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Internet Procurement Connector permits an attacker without authentication to send HTTP requests that can create, delete, or modify critical data. The flaw results in a loss of confidentiality and integrity for all data accessible through the connector, potentially allowing complete data compromise.

Affected Systems

The affected product is Oracle Internet Procurement Connector, available in Oracle E‑Business Suite versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS 3.1 base score of 7.4 indicates a high level of risk, even though exploitation is described as difficult. The EPSS score is < 1%, indicating a very low probability of exploitation, and the issue has not been listed in CISA’s KEV catalog. However, the remote network access requirement and lack of authentication requirement mean that an adversary with network visibility could attempt exploitation. The vulnerability’s impact on confidentiality and integrity warrants immediate remediation once a patch is released.

Generated by OpenCVE AI on August 21, 2026 at 15:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch or update for Oracle Internet Procurement Connector when it becomes available.
  • Restrict HTTP access to the connector using firewall or network segmentation so only trusted internal hosts can reach it.
  • If the connector is not required for critical operations, temporarily disable or block its web service to prevent exploitation.
  • Monitor application and web‑server logs for anomalous requests that indicate attempts to use the vulnerable functionality.

Generated by OpenCVE AI on August 21, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Internet Procurement Connector via Unauthenticated HTTP

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle internet Procurement Connector
CPEs cpe:2.3:a:oracle:internet_procurement_connector:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle internet Procurement Connector
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Internet Procurement Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:19:52.248Z

Reserved: 2026-07-08T15:51:55.588Z

Link: CVE-2026-60759

cve-icon Vulnrichment

Updated: 2026-08-20T19:19:46.447Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T21:16:42.390

Modified: 2026-08-20T20:17:36.117

Link: CVE-2026-60759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:30:05Z

Weaknesses