Description
Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Intelligence accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle E-Business Intelligence permits an attacker with high privileges and network access to create, delete, or modify critical data. This grants the attacker unauthorized control over the system’s data assets, leading to confidentiality and integrity breaches without affecting availability.

Affected Systems

Affected are Oracle E-Business Intelligence versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite. These are the only documented vulnerable releases. The issue is specific to the Internal Operations component of the product.

Risk and Exploitability

The CVSS 3.1 base score of 5.9 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation and it is not listed in CISA’s KEV catalog. The vulnerability is accessed over the network via HTTP, likely requiring attackers to have network connectivity to the affected system and, as inferred from the CVSS vector, likely requiring elevated authorization before exploitation. Likely, a compromise of a service account would permit full data manipulation within the scope of that account’s permissions.

Generated by OpenCVE AI on August 5, 2026 at 01:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or update provided in Oracle CPU Jul 2026 to all affected Oracle E‑Business Intelligence installations
  • Configure network firewalls or web‑application gateways to restrict HTTP access to the E‑Business Intelligence service to trusted IP ranges only
  • Review and tighten internal operation service account privileges to ensure only necessary permissions are granted

Generated by OpenCVE AI on August 5, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification Vulnerability in Oracle E‑Business Intelligence
Weaknesses CWE-285

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle E-Business Intelligence via HTTP
Weaknesses CWE-285
CWE-732

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle E-Business Intelligence via HTTP
Weaknesses CWE-285
CWE-732

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle E-Business Intelligence
Weaknesses CWE-285

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle E-Business Intelligence
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Intelligence accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle e-business Intelligence
CPEs cpe:2.3:a:oracle:e-business_intelligence:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle e-business Intelligence
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle E-business Intelligence E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:19:54.776Z

Reserved: 2026-07-08T15:51:55.591Z

Link: CVE-2026-60801

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:18.753

Modified: 2026-08-03T11:47:31.210

Link: CVE-2026-60801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:45:04Z

Weaknesses