Description
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Search Bean component of Oracle Applications Framework, part of Oracle E‑Business Suite. It allows an attacker with low privileges who can reach the application over HTTP to compromise the framework. Successful exploitation can lead to unauthorized access to critical data and, in some cases, the ability to insert, update, or delete data available through the framework. The CVSS 3.1 score of 7.1 reflects significant confidentiality damage and moderate integrity impact.

Affected Systems

Oracle Applications Framework in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 is affected. The flaw impacts the Search Bean (including Advanced) component that handles search functionality exposed over HTTP.

Risk and Exploitability

The risk is moderate to high; the CVSS score indicates serious confidentiality loss. The EPSS score of less than 1 % suggests that, at the time of analysis, real‑world exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be network via HTTP with low conduct privilege, meaning that any user who can reach the exposed component may exploit the flaw as long as they can send crafted HTTP requests to it.

Generated by OpenCVE AI on August 4, 2026 at 02:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Critical Patch Update released for CVE‑2026‑60774 to all affected Applications Framework instances.
  • Restrict network access to the Search Bean endpoints, limiting exposure to trusted hosts or internal networks.
  • Enforce strict role‑based access controls so that only authorized users can perform data modification operations through the Search Bean.
  • Enable detailed logging for Search Bean activities and monitor for anomalous write operations.

Generated by OpenCVE AI on August 4, 2026 at 02:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Allows Unauthorized Data Modification in Oracle Applications Framework

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Allows Unauthorized Data Modification in Oracle Applications Framework

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Allows Unauthorized Data Modification in Oracle Applications Framework
Weaknesses CWE-285

Sun, 26 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Allows Unauthorized Data Modification in Oracle Applications Framework
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle applications Framework
CPEs cpe:2.3:a:oracle:applications_framework:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Framework
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Applications Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:04:47.930Z

Reserved: 2026-07-08T15:51:55.589Z

Link: CVE-2026-60774

cve-icon Vulnrichment

Updated: 2026-07-24T19:04:40.471Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:16.560

Modified: 2026-07-30T17:37:11.157

Link: CVE-2026-60774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses