Description
Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability enables a low‑privileged attacker who can reach the Oracle Compensation Workbench over HTTP to bypass the application’s intended access controls. This allows unauthorized reading of critical data (high confidentiality impact) and modification operations such as insert, update, or delete (moderate integrity impact) on tables accessible through the workbench. The weakness is rooted in insufficient authorization checks.

Affected Systems

Oracle Compensation Workbench from Oracle Corporation is affected. The flaw applies to all supported versions between 12.2.3 and 12.2.15 inclusive, covering the Compensation Workbench component of Oracle E‑Business Suite.

Risk and Exploitability

The CVSS 3.1 Base Score of 7.1 indicates a high risk to confidentiality, with a low to medium likelihood of exploitation (EPSS <1%) and no listing in CISA’s KEV catalog. The exploit can be carried out remotely via the HTTP interface with only low privilege. Successful exploitation grants unauthorized access to and modification of the work data but does not extend to full system compromise.

Generated by OpenCVE AI on August 5, 2026 at 01:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle Compensation Workbench patches as soon as they become available
  • Monitor Oracle security advisories for new releases
  • Restrict HTTP exposure by configuring network segmentation or firewall rules so that only trusted administrative hosts can reach Compensation Workbench
  • Continuously audit and monitor database logs for unauthorized insert, update, or delete activity on Compensation Workbench tables

Generated by OpenCVE AI on August 5, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability Enables Unauthorized Data Access and Modification in Oracle Compensation Workbench
Weaknesses CWE-284

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Low-privileged HTTP Access to Oracle Compensation Workbench Allows Unauthorized Data Manipulation
Weaknesses CWE-284
CWE-285

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Low-privileged HTTP Access to Oracle Compensation Workbench Allows Unauthorized Data Manipulation
Weaknesses CWE-284
CWE-285

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification via HTTP in Oracle Compensation Workbench
Weaknesses CWE-284

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification via HTTP in Oracle Compensation Workbench
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle compensation Workbench
CPEs cpe:2.3:a:oracle:compensation_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle compensation Workbench
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Compensation Workbench E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:20:01.925Z

Reserved: 2026-07-08T15:51:55.591Z

Link: CVE-2026-60800

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:18.650

Modified: 2026-08-07T21:15:18.847

Link: CVE-2026-60800

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses