Description
Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in takeover of Oracle Sales Offline. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Sales Offline contains an improper access control flaw that lets a low‑privileged user with network access via HTTP execute privileged actions and ultimately takeover the application. The CVSS v3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H reflects high impact on confidentiality, integrity, and availability.

Affected Systems

Oracle Corporation’s Oracle Sales Offline component of Oracle E‑Business Suite versions 12.2.3 through 12.2.15 is affected. The issue resides in the internal operations module of Sales Offline.

Risk and Exploitability

The CVSS base score of 8.8 indicates a high‑severity vulnerability, while the EPSS score of less than 1 % and absence from CISA’s KEV catalog suggest a low current exploitation probability. An attacker would need only low‑privilege credentials and HTTP network access to the Sales Offline instance to launch the attack, after which full control over the application can be achieved.

Generated by OpenCVE AI on August 5, 2026 at 04:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Sales Offline patch that addresses the improper access control flaw for the affected versions.
  • Restrict inbound HTTP traffic to the Sales Offline instance by firewall rules or a web application firewall to allow only trusted IP ranges.
  • Enforce strict role‑based access control on the internal operations module so that only authorized users can perform privileged actions.

Generated by OpenCVE AI on August 5, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Sales Offline Allows Low-Privilege Takeover
Weaknesses CWE-284

Wed, 05 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Attack Enables Full Takeover of Oracle Sales Offline
Weaknesses CWE-284

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Attack Enables Full Takeover of Oracle Sales Offline
Weaknesses CWE-284

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle Sales Offline (E-Business Suite)
Weaknesses CWE-284

Sun, 26 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle Sales Offline (E-Business Suite)
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in takeover of Oracle Sales Offline. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle sales Offline
CPEs cpe:2.3:a:oracle:sales_offline:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle sales Offline
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Sales Offline
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:29:38.545Z

Reserved: 2026-07-08T15:51:55.590Z

Link: CVE-2026-60789

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:17.960

Modified: 2026-07-27T17:33:22.680

Link: CVE-2026-60789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T04:30:17Z

Weaknesses