Description
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Bills of Material allows a low‑privileged attacker who can reach the application through an HTTP connection to compromise the system. The flaw enables a successful attacker to achieve full takeover of Oracle Bills of Material, affecting confidentiality, integrity, and availability. The weakness is consistent with an exploitation of improper privilege escalation or improper access control.

Affected Systems

Oracle Bills of Material in Oracle E‑Business Suite platforms, specifically Oracle Corporation’s Oracle Bills of Material product, is affected for releases between 12.2.3 and 12.2.15 inclusive. These deployments typically expose an HTTP interface that an external attacker can reach over the network.

Risk and Exploitability

The CVSS v3.1 Base Score of 8.0 indicates a high‑severity risk, but the EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting low likelihood of exploitation in the wild. The attack requires network access via HTTP, a low privileged attacker, and user interaction—indicating a social‑engineering component, but the low authentication requirement and remote nature lower the barriers to entry.

Generated by OpenCVE AI on August 2, 2026 at 20:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for CVE‑2026‑60807 or upgrade to a non‑affected release
  • Restrict network access to the Oracle Bills of Material HTTP interface to trusted hosts or use firewall rules
  • Ensure application accounts use the principle of least privilege and enforce strong authentication

Generated by OpenCVE AI on August 2, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote HTTP Privilege Escalation in Oracle Bills of Material

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attack Enables Takeover of Oracle Bills of Material
Weaknesses CWE-200
CWE-269

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 26 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attack Enables Takeover of Oracle Bills of Material
Weaknesses CWE-200
CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle bills Of Material
CPEs cpe:2.3:a:oracle:bills_of_material:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bills Of Material
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Bills Of Material
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T14:56:25.744Z

Reserved: 2026-07-08T15:51:55.592Z

Link: CVE-2026-60807

cve-icon Vulnrichment

Updated: 2026-07-28T13:41:23.199Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:00:06Z

Weaknesses