Description
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSupport accessible data. CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle iSupport allows an unauthenticated attacker who can reach the service over HTTP to alter the integrity. The weakness is an improper access control that permits creation, deletion, or modification of critical information, potentially affecting all data accessible through iSupport. Because the vulnerability updates a scope boundary, successful exploitation could also impact additional components of the Oracle E‑Business Suite.

Affected Systems

Oracle iSupport, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS v3.1 base score of 7.4 indicates a high impact on integrity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network access via HTTP and requires no authentication; the attacker must also obtain assistance from a separate individual, implying a combined technical and social engineering effort. The scope change means that exploitation may extend to other related components beyond the directly vulnerable iSupport instance.

Generated by OpenCVE AI on August 4, 2026 at 16:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle iSupport patch as outlined in the Oracle CPU July 2026 advisory
  • Restrict external HTTP access to the iSupport service by configuring firewalls or VPNs to allow only trusted network segments
  • Implement monitoring for unauthorized data modifications and enforce strict access controls; provide security awareness training to mitigate social‑engineering attempts

Generated by OpenCVE AI on August 4, 2026 at 16:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Oracle iSupport Access Control Vulnerability Enabling Unauthorized Data Modification
Weaknesses CWE-284

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Integrity Compromise in Oracle iSupport
Weaknesses CWE-284

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Integrity Compromise in Oracle iSupport
Weaknesses CWE-284

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Integrity Compromise in Oracle iSupport
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Integrity Compromise in Oracle iSupport
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSupport accessible data. CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).
First Time appeared Oracle
Oracle isupport
CPEs cpe:2.3:a:oracle:isupport:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isupport
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:18:24.780Z

Reserved: 2026-07-08T15:51:55.593Z

Link: CVE-2026-60827

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:20.670

Modified: 2026-07-31T17:42:54.163

Link: CVE-2026-60827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:45:04Z

Weaknesses