Description
Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in the Internal Operations component of Oracle Price Protection, part of Oracle E‑Business Suite. It is an information disclosure flaw (CWE-200) that allows a low‑privileged attacker with network access over HTTP to read critical data exposed by the service. Successful exploitation would enable the attacker to access all data available through Price Protection, resulting in a confidentiality breach without impacting integrity or availability.

Affected Systems

Oracle Price Protection versions from 12.2.3 through 12.2.15 are affected. Administrators should confirm whether those releases are in use and review their current system configuration.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 reflects medium overall severity, driven by a high confidentiality impact (C:H). The EPSS score is below 1%, indicating that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires only network access to the HTTP endpoint and does not need elevated privileges, making it reachable by low‑privileged users on the same network segment.

Generated by OpenCVE AI on August 2, 2026 at 20:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Price Protection security patch released in the July 2026 CPU cycle.
  • Restrict HTTP access to the Price Protection service by configuring firewall rules or access control lists to allow only trusted hosts.
  • Ensure the service is accessed exclusively by privileged accounts and revoke any unused or low‑privilege service accounts.

Generated by OpenCVE AI on August 2, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Information Disclosure in Oracle Price Protection Over HTTP

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Insecure HTTP Access in Oracle Price Protection Enables Unauthorized Data Access

Mon, 27 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Insecure HTTP Access in Oracle Price Protection Enables Unauthorized Data Access

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle price Protection
CPEs cpe:2.3:a:oracle:price_protection:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle price Protection
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Price Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:26:10.201Z

Reserved: 2026-07-08T15:51:55.594Z

Link: CVE-2026-60835

cve-icon Vulnrichment

Updated: 2026-07-24T18:26:04.465Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:00:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor