Description
Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle E-Business Intelligence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data as well as unauthorized read access to a subset of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle E‑Business Intelligence allows an unauthenticated attacker with network access via HTTP to compromise the system, resulting in unauthorized update and delete operations as well as read access to a subset of data. The weakness involves improper authorization controls, limiting confidentiality and integrity but not availability. The CVSS 3.1 Base Score is 6.1, indicating a medium severity with medium confidence in the impact figures.

Affected Systems

The affected product is Oracle E‑Business Intelligence included in Oracle E‑Business Suite, specifically the Internal Operations component. Versions from 12.2.3 through 12.2.15 are impacted. Users running any of these releases are at risk if the software is exposed to HTTP traffic.

Risk and Exploitability

The attack vector requires an unauthenticated HTTP connection and human interaction from a non‑attacker, which limits the likelihood of successful exploitation. The CVSS 3.1 Base Score of 6.1 indicates medium confidentiality and integrity impact, and the vector shows a scope change (S:C), meaning this vulnerability in Oracle E‑Business Intelligence could also affect additional Oracle products. The EPSS score is less than 1 %, indicating a very low probability of immediate exploitation, and the vulnerability is not listed in KEV. Given the potential for data loss or modification, the risk remains significant for organizations that keep the exposed interfaces online.

Generated by OpenCVE AI on August 5, 2026 at 01:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether the installed Oracle E‑Business Intelligence version falls within the affected range and apply the latest patch or upgrade to a fixed version.
  • Configure network firewalls or security groups to restrict HTTP access to Oracle E‑Business Intelligence endpoints.
  • Enable detailed logging of all HTTP transactions and regularly review logs for unauthorized update or read attempts, and set alerts for anomalous activity.

Generated by OpenCVE AI on August 5, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authorization Bypass in Oracle E-Business Intelligence
Weaknesses CWE-284

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle E‑Business Intelligence
Weaknesses CWE-284

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle E‑Business Intelligence
Weaknesses CWE-284

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated HTTP in Oracle E‑Business Intelligence
Weaknesses CWE-285

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated HTTP in Oracle E‑Business Intelligence
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle E-Business Intelligence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Intelligence accessible data as well as unauthorized read access to a subset of Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle e-business Intelligence
CPEs cpe:2.3:a:oracle:e-business_intelligence:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle e-business Intelligence
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle E-business Intelligence E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:19:46.790Z

Reserved: 2026-07-08T15:51:55.592Z

Link: CVE-2026-60802

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:18.870

Modified: 2026-08-03T11:45:32.113

Link: CVE-2026-60802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:45:04Z

Weaknesses