Description
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a high privileged attacker with network access via HTTP to compromise the Oracle iSupport component of Oracle E‑Business Suite. Successful exploitation can result in full takeover of the iSupport service, exposing confidential operational data and compromising the confidentiality, integrity, and availability of the affected system.

Affected Systems

Oracle Corporation’s Oracle iSupport component of Oracle E‑Business Suite is affected for versions 12.2.3 through 12.2.15. These versions provide internal operations and support functions accessed over HTTP.

Risk and Exploitability

The CVSS 3.1 base score of 6.6 indicates significant impact on confidentiality, integrity, and availability, while the EPSS score of less than 1 % suggests a low likelihood of widespread exploitation at present. Because the flaw requires a high privileged attacker to reach the iSupport HTTP endpoint, the practical attack vector is limited. The vulnerability is not listed in the CISA KEV Catalog, but if exploited the attacker could achieve full control over the iSupport service, compromising confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 5, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle iSupport patch available in the Oracle CPU July 2026 advisory.
  • Restrict network access to the iSupport HTTP interface by configuring firewalls or network segmentation so that only trusted administrative hosts can reach it.
  • Monitor iSupport logs for anomalous authentication or privilege escalation events and perform regular security audits to detect potential abuse.

Generated by OpenCVE AI on August 5, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Network Exploit Enables Oracle iSupport Takeover
Weaknesses CWE-285

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Service Takeover via HTTP in Oracle iSupport
Weaknesses CWE-272
CWE-284

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Service Takeover via HTTP in Oracle iSupport
Weaknesses CWE-272
CWE-284

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle iSupport Leading to Service Compromise
Weaknesses CWE-272
CWE-284

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle iSupport Leading to Service Compromise
Weaknesses CWE-272
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle isupport
CPEs cpe:2.3:a:oracle:isupport:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isupport
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:18:39.526Z

Reserved: 2026-07-08T15:51:55.593Z

Link: CVE-2026-60825

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:20.450

Modified: 2026-07-30T17:38:01.497

Link: CVE-2026-60825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses