Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as unauthorized read access to a subset of Oracle Application Object Library accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Object Library. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker with network access to the Oracle Application Object Library can exploit a vulnerability that enables unauthorized update, insert, or delete operations on accessible data, as well as read a subset of that data and trigger a partial denial of service. The impact spans confidentiality, integrity, and availability, with a CVSS v3.1 base score of 6.3 indicating a moderate but significant risk to the exposed information and system function.

Affected Systems

Oracle Application Object Library, part of Oracle E‑Business Suite Core, is vulnerable in all supported releases from 12.2.3 through 12.2.15, as noted in the vendor’s advisory.

Risk and Exploitability

The attack vector is a network‑based HTTP connection that requires low privilege and no user interaction. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the moderate CVSS score and the potential for non‑trivial data compromise and service interruption warrant a timely remediation effort.

Generated by OpenCVE AI on August 4, 2026 at 02:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official Oracle patch or upgrade to a release outside the 12.2.3–12.2.15 range when available
  • Restrict HTTP access to the Application Object Library, confining it to trusted IP ranges or internal networks and enforce least‑privilege access controls for low‑privileged accounts
  • Implement monitoring for anomalous data modification, insertion, or deletion attempts and for signs of partial service degradation to detect exploitation early

Generated by OpenCVE AI on August 4, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via HTTP in Oracle Application Object Library
Weaknesses CWE-200
CWE-284

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via HTTP in Oracle Application Object Library
Weaknesses CWE-284
CWE-639

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Oracle Application Object Library Data Manipulation and Partial DoS via HTTP

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Oracle Application Object Library Data Manipulation and Partial DoS via HTTP
Weaknesses CWE-284
CWE-639

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as unauthorized read access to a subset of Oracle Application Object Library accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Object Library. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:21:33.893Z

Reserved: 2026-07-08T15:51:55.589Z

Link: CVE-2026-60777

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:16.913

Modified: 2026-07-29T15:33:55.453

Link: CVE-2026-60777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control