Description
Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Enterprise Asset Management allows a low‑privileged attacker with network access over HTTP to gain unauthorized write and read capabilities against certain data sets. The flaw is described as difficult to exploit, yet once exploited it permits the attacker to modify or delete records and read restricted information, leading to integrity and confidentiality breaches.

Affected Systems

Oracle Enterprise Asset Management within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected.

Risk and Exploitability

With a CVSS 3.1 base score of 4.2, the severity is moderate. The EPSS score of less than 1% indicates a low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Attackers would need network access to the HTTP interface and a low privilege account, and would likely exploit the application’s insufficient access controls.

Generated by OpenCVE AI on August 4, 2026 at 02:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify which Oracle Enterprise Asset Management version you are running and apply Oracle’s security patch for CVE‑2026‑60760 as soon as it is available.
  • Restrict HTTP and other inbound traffic to the Oracle Enterprise Asset Management service using firewall rules so that only trusted internal hosts can reach it.
  • Enforce strict role‑based access controls, ensuring that low‑privilege accounts cannot perform update, insert, or delete operations on protected data.

Generated by OpenCVE AI on August 4, 2026 at 02:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Access Vulnerability in Oracle Enterprise Asset Management

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification Vulnerability in Oracle Enterprise Asset Management

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification Vulnerability in Oracle Enterprise Asset Management
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Enterprise Asset Management accessible data as well as unauthorized read access to a subset of Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle enterprise Asset Management
CPEs cpe:2.3:a:oracle:enterprise_asset_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Asset Management
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Enterprise Asset Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:22:41.168Z

Reserved: 2026-07-08T15:51:55.588Z

Link: CVE-2026-60760

cve-icon Vulnrichment

Updated: 2026-07-24T15:15:15.897Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:15.380

Modified: 2026-08-03T16:18:24.837

Link: CVE-2026-60760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses