Description
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Cost Management. CVSS 3.1 Base Score 6.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-07-21
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Cost Planning component of Oracle Cost Management provides improper access control. An attacker with high privileges who can reach the service over HTTP can create, delete or modify critical data. The compromise also allows the attacker to cause a partial denial of service, impacting the ability to perform some operations. The weakness results in confidentiality, integrity, and availability impacts as reflected in the CVSS 3.1 score.

Affected Systems

Oracle Corporation’s Oracle Cost Management, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The vulnerability specifically targets the Cost Planning component of this product.

Risk and Exploitability

The CVSS v3.1 score of 6.2 indicates moderate severity, with impacts to confidentiality, integrity, and availability. The EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires an attacker to possess high‑privilege credentials within the network and to access the service over HTTP. Successful exploitation would enable the attacker to alter critical data or partially disrupt service availability.

Generated by OpenCVE AI on August 5, 2026 at 01:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict HTTP access to the Cost Management service to trusted internal hosts using firewall or network segmentation.
  • Enforce strict role‑based access control for the Cost Planning component, ensuring only authorized privileged users can create, delete, or modify critical data.
  • Implement continuous monitoring and audit logging of Cost Planning operations to detect unauthorized manipulation or denial‑of‑service attempts.

Generated by OpenCVE AI on August 5, 2026 at 01:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title High-Privilege Access Control Failure in Oracle Cost Management Allows Data Manipulation and Partial DoS
Weaknesses CWE-284

Sun, 02 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Cost Management Enables Unauthorized Data Manipulation and Partial DoS
Weaknesses CWE-284

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Cost Management Enables Unauthorized Data Manipulation and Partial DoS
Weaknesses CWE-284

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Network-Based Privileged Attack Allows Unauthorized Data Modification in Oracle Cost Management
Weaknesses CWE-284

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Network-Based Privileged Attack Allows Unauthorized Data Modification in Oracle Cost Management
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Cost Management. CVSS 3.1 Base Score 6.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle cost Management
CPEs cpe:2.3:a:oracle:cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle cost Management
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle Cost Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:19:31.435Z

Reserved: 2026-07-08T15:51:55.592Z

Link: CVE-2026-60805

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:19.097

Modified: 2026-07-29T14:47:24.360

Link: CVE-2026-60805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:45:04Z

Weaknesses