Description
Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.14-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. While the vulnerability is in Oracle Advanced Pricing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Advanced Pricing includes a vulnerability that allows a low‑privileged attacker who can reach the service over HTTP to compromise the application, gaining unauthorized access to critical data. Successful exploitation can result in full access to all data available through the Oracle Advanced Pricing component, as well as the ability to update, insert, or delete entries. The vulnerability’s status is noted as difficult to exploit, indicating a non‑trivial attack surface, but the impact to confidentiality and integrity is significant.

Affected Systems

The affected product is Oracle Advanced Pricing from Oracle Corporation, specifically versions 12.2.14 and 12.2.15 of the Pricing Installation component. Because the vulnerability is marked as changing scope, systems that rely on Oracle Advanced Pricing may also be impacted even if they are not directly exposed.

Risk and Exploitability

The base CVSS score is 7.1, indicating a high‑severity issue that primarily affects confidentiality and integrity. The EPSS score is currently below 1 %, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network access to the HTTP endpoint of Advanced Pricing and is possible for users with low privilege; however, the documented difficulty raises the attack complexity. The combined effect is a moderate threat that could have broader implications for other Oracle E‑Business Suite products due to the scope change.

Generated by OpenCVE AI on August 4, 2026 at 16:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Advanced Pricing to a version later than 12.2.15 to include the vendor’s fix
  • Configure network controls (firewalls or ACLs) to restrict HTTP access to the Advanced Pricing service to trusted, privileged hosts only
  • Audit and review user privileges on the Advanced Pricing component, ensuring that only authorized accounts can perform update, insert, or delete operations

Generated by OpenCVE AI on August 4, 2026 at 16:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Unauthorized Data Access and Modification in Oracle Advanced Pricing

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Unauthorized Data Access and Modification in Oracle Advanced Pricing

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Low‑Privilege Attack Enables Unauthorized Data Access in Oracle Advanced Pricing
Weaknesses CWE-285

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Low‑Privilege Attack Enables Unauthorized Data Access in Oracle Advanced Pricing
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.14-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. While the vulnerability is in Oracle Advanced Pricing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle advanced Pricing
CPEs cpe:2.3:a:oracle:advanced_pricing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Pricing
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Advanced Pricing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:13:48.379Z

Reserved: 2026-07-08T15:51:55.597Z

Link: CVE-2026-60868

cve-icon Vulnrichment

Updated: 2026-07-24T17:43:41.657Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:23.800

Modified: 2026-07-29T20:17:08.293

Link: CVE-2026-60868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:45:04Z

Weaknesses