Description
Vulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Pasta executes to compromise Pasta. Successful attacks of this vulnerability can result in takeover of Pasta. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An internally detectable flaw in Oracle Pasta, a component of Oracle E‑Business Suite, allows a high‑privileged user who has logged on to the host where Pasta runs to exploit the application and fully compromise it. The successful exploitation results in the attacker taking control of Pasta, thereby exposing or manipulating sensitive business data, bypassing controls, and potentially disrupting critical services.

Affected Systems

The vulnerability affects Oracle Corporation’s Pasta product within Oracle E‑Business Suite, specifically the Internal Operations module. Supported versions that are impacted are 12.2.3 through 12.2.15. No other vendors or versions are listed as affected.

Risk and Exploitability

The CVSS v3.1 base score of 6.7 indicates moderate severity with high impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests exploitation is unlikely but still possible, especially to users with local system access. The vulnerability is not listed in the CISA KEV catalog, meaning no known widespread exploitation at this time. The attack vector is inferred to be local (AV:L) and requires an attacker to have high‑privilege credentials on the underlying host; once achieved, the exploit can be executed with no user interaction (UI:N).

Generated by OpenCVE AI on August 2, 2026 at 21:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Pasta as soon as it becomes available or upgrade to a supported version newer than 12.2.15
  • Restrict local accounts on the infrastructure hosting Pasta to the minimum required privileges, enforcing a least‑privilege model
  • Monitor system logs for unusual activity related to Pasta, such as unauthorized changes to configuration or unexpected process execution

Generated by OpenCVE AI on August 2, 2026 at 21:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title High Privilege Local Exploit in Oracle Pasta

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Pasta Allowing Full Compromise
Weaknesses CWE-269

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Pasta Allowing Full Compromise
Weaknesses CWE-269

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Pasta executes to compromise Pasta. Successful attacks of this vulnerability can result in takeover of Pasta. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle pasta
CPEs cpe:2.3:a:oracle:pasta:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle pasta
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle E-business Suite Pasta
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:59:15.418Z

Reserved: 2026-07-08T15:51:55.589Z

Link: CVE-2026-60775

cve-icon Vulnrichment

Updated: 2026-07-24T18:59:08.845Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:16.680

Modified: 2026-08-06T15:07:49.027

Link: CVE-2026-60775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses