Description
Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a difficult‑to‑exploit remote flaw in Oracle Quality that permits an attacker with low privileges but network access over HTTP to compromise the product. When successfully exploited, it allows full takeover of Oracle Quality, compromising confidentiality, integrity, and availability as reflected by the CVSS score.

Affected Systems

It affects Oracle Corporation’s Oracle Quality component of Oracle E‑Business Suite, specifically the Internal Operations module in versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 classifies this issue as high severity, yet the EPSS score of less than 1% indicates a very low probability of real exploitation, and the description notes it is difficult to exploit. Because the attack vector is network‑based over HTTP and requires only a low‑privilege attacker, organizations should treat systems exposed to the network as potentially vulnerable within the same subnet.

Generated by OpenCVE AI on August 2, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Conduct a vulnerability assessment to confirm whether an Oracle Quality patch is available, then apply the quickest available fix from Oracle.
  • Restrict external HTTP access to the Oracle Quality service to a trusted IP range or network zone, or place the service behind a firewall that blocks untrusted traffic.
  • Continuously monitor Oracle Quality logs and network traffic for abnormal authentication attempts or configuration changes, and enforce strict role‑based access control to minimize privileges for low‑privilege accounts.

Generated by OpenCVE AI on August 2, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Low-privilege HTTP Exploit Enables Full Oracle Quality Takeover

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Low-privilege HTTP Exploit Enables Full Oracle Quality Takeover

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle quality
CPEs cpe:2.3:a:oracle:quality:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle quality
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle E-business Suite Quality
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:19:21.442Z

Reserved: 2026-07-08T15:51:55.596Z

Link: CVE-2026-60855

cve-icon Vulnrichment

Updated: 2026-07-24T18:19:08.063Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:22.993

Modified: 2026-07-30T18:36:25.420

Link: CVE-2026-60855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:45:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function