Description
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized read access to a subset of Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Financials Common Modules allows a low‑privileged attacker with network access over HTTP to perform unauthorized creation, deletion, modification, and read operations on critical data. The flaw provides a breach of confidentiality and integrity without affecting availability. The vulnerability is an instance of improper access control, enabling attackers to manipulate or view data they should not be able to access.

Affected Systems

Oracle Corporation – Oracle Financials Common Modules (Oracle E‑Business Suite, Common Components). Versions from 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The vulnerability scores a CVSS 3.1 base of 7.1, indicating a high impact on confidentiality and integrity. The EPSS score is below 1%, implying limited yet still possible exploitation. It is not included in CISA’s KEV catalog. The CVSS vector points to network attack, low authentication, and user interface absence, and the description indicates the attacker must be a low‑privileged user with HTTP access, suggesting that the exploit likely requires an application‑level authentication context or misconfigured access controls within the module.

Generated by OpenCVE AI on August 4, 2026 at 02:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch release for Oracle Financials Common Modules covering versions 12.2.3–12.2.15 from Oracle’s latest security update package
  • Restrict HTTP access to the Oracle Financials Common Modules endpoints to trusted network subnets or VPN gates and enforce firewall rules to limit exposure to known administrators
  • Enable role‑based access control in the application, audit logs for data modification and read actions, and review permissions to ensure least privilege

Generated by OpenCVE AI on August 4, 2026 at 02:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Access Allows Unauthorized Data Manipulation in Oracle Financials Common Modules

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploit Allows Unauthorized Access to Oracle Financials Common Modules

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploit Allows Unauthorized Access to Oracle Financials Common Modules
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized read access to a subset of Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
First Time appeared Oracle
Oracle financials Common Modules
CPEs cpe:2.3:a:oracle:financials_common_modules:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle financials Common Modules
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Oracle E-business Suite Financials Common Modules
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:03:22.188Z

Reserved: 2026-07-08T15:51:55.589Z

Link: CVE-2026-60772

cve-icon Vulnrichment

Updated: 2026-07-24T19:03:17.327Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:16.327

Modified: 2026-08-07T21:16:12.987

Link: CVE-2026-60772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses