Description
Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via RMI to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Interaction Blending accessible data as well as unauthorized read access to a subset of Oracle Interaction Blending accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Interaction Blending. CVSS 3.1 Base Score 4.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the Oracle Interaction Blending component of Oracle E-Business Suite, where a high-privileged attacker who can reach the RMI interface from the network can exploit a difficult-to-exploit weakness to perform unauthorized updates, inserts, or deletes, read restricted data, and trigger a partial denial of service. The vulnerability does not provide remote code execution but enables modification of application data and availability impact, as reflected by a CVSS 3.1 score of 4.1. Based solely on the description, it is inferred that the attack vector is via the RMI network channel and requires the attacker to possess high privileges on the host or the ability to act as an authenticated user.

Affected Systems

Affected products are Oracle Corporation’s Oracle Interaction Blending for Oracle E-Business Suite, in the supported versions 12.2.3 through 12.2.15. Users running any of these releases should verify their product version against this range.

Risk and Exploitability

The CVSS score and the EPSS score of less than 1 % indicate a low but present risk; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a network-connected RMI service and a high-privileged attacker, suggesting that while the attack surface is limited, sufficient internal access would let an attacker gain unauthorized data control and achieve a partial denial of service.

Generated by OpenCVE AI on August 4, 2026 at 02:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to an unaffected release of Oracle Interaction Blending to resolve the improper access control flaw identified by CWE‑284.
  • Restrict network access to the RMI interface by configuring firewall rules or VPN to allow only trusted internal hosts, ensuring that only authorized users can reach the service.
  • Implement strict authorization checks on all RMI operations to enforce proper access control, limiting update, insert, delete, and read actions to the appropriate user roles.
  • Enable and regularly review audit logging for RMI activity to detect unauthorized privileged operations and potential misuse.

Generated by OpenCVE AI on August 4, 2026 at 02:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification, Read Access, and Partial Denial of Service via RMI in Oracle Interaction Blending

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification, Read Access, and Partial Denial of Service via RMI in Oracle Interaction Blending

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title High‑Privilege RMI Vulnerability in Oracle Interaction Blending
Weaknesses CWE-287

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege RMI Vulnerability in Oracle Interaction Blending
Weaknesses CWE-284
CWE-287
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via RMI to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Interaction Blending accessible data as well as unauthorized read access to a subset of Oracle Interaction Blending accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Interaction Blending. CVSS 3.1 Base Score 4.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle interaction Blending
CPEs cpe:2.3:a:oracle:interaction_blending:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle interaction Blending
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Interaction Blending
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:28:14.659Z

Reserved: 2026-07-08T15:51:55.594Z

Link: CVE-2026-60832

cve-icon Vulnrichment

Updated: 2026-07-24T18:28:10.821Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:21.007

Modified: 2026-07-31T17:28:45.477

Link: CVE-2026-60832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:45:02Z

Weaknesses