Description
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSetup accessible data as well as unauthorized access to critical data or complete access to all Oracle iSetup accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the General Ledger Update Transform and Reports components of Oracle iSetup. It allows a low‑privilege attacker that can reach the service over HTTP to create, delete, or modify critical data and to access data that should be restricted. The flaw results in confidentiality and integrity violations, enabling unauthorized data handling without affecting availability.

Affected Systems

The affected product is Oracle iSetup, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are vulnerable. No other versions are impacted according to the available data.

Risk and Exploitability

Score 6.8 indicates medium severity, and EPSS below 1 % reflects a very low expected exploitation probability at this time. The flaw can be exercised remotely over the network using HTTP, requiring only low privileges. Although it does not affect availability, it permits unauthorized creation, deletion or modification of critical data, including full access to all data that Oracle iSetup can reach. The vulnerability is not listed in the CISA KEV catalog. Organizations with exposed Oracle iSetup instances should assess exposure and apply mitigations promptly.

Generated by OpenCVE AI on August 2, 2026 at 20:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle iSetup patch or upgrade to a patched version, typically 12.2.16 or newer, following the vendor’s release notes.
  • Restrict network access to the iSetup service by configuring firewalls to allow only trusted hosts to connect over HTTP.
  • Strengthen role‑based access control, ensuring that only users with appropriate permissions can perform critical ledger modifications, and monitor for unauthorized data changes.

Generated by OpenCVE AI on August 2, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle iSetup

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle iSetup

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Oracle iSetup Unauthorized Data Access Vulnerability
Weaknesses CWE-20

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Oracle iSetup Unauthorized Data Access Vulnerability
Weaknesses CWE-20
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSetup accessible data as well as unauthorized access to critical data or complete access to all Oracle iSetup accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle isetup
CPEs cpe:2.3:a:oracle:isetup:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isetup
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:20:18.845Z

Reserved: 2026-07-08T15:51:55.591Z

Link: CVE-2026-60795

cve-icon Vulnrichment

Updated: 2026-07-24T15:03:56.410Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:18.420

Modified: 2026-07-29T14:51:25.210

Link: CVE-2026-60795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:00:06Z

Weaknesses