Description
Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Advanced Pricing component in E‑Business Suite contains a vulnerability that allows a low‑privileged attacker who can reach the system over HTTP to gain unauthorized access to critical data or to all accessible data. Successful exploitation also permits the attacker to perform update, insert or delete operations on that data. This weakness is a case of broken access control (CWE-284) and directly impacts confidentiality and integrity as reflected in its CVSS 3.1 base score of 7.1.

Affected Systems

Oracle Advanced Pricing for E‑Business Suite versions 12.2.3 through 12.2.15 are affected. Any deployment that includes the Pricing Installation component is at risk if not patched.

Risk and Exploitability

The CVSS rating of 7.1 indicates high severity, while the EPSS score of less than 1% shows a very low probability of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. Attackers can exploit the weakness over HTTP with minimal privileges, enabling them to compromise data confidentiality and integrity.

Generated by OpenCVE AI on August 2, 2026 at 20:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Advanced Pricing patches or upgrade to a version where the vulnerability is fixed
  • Restrict HTTP access to the Advanced Pricing component by implementing firewall rules or network segmentation to limit connections to trusted hosts
  • Enforce strict least privilege management for user accounts accessing Oracle Advanced Pricing, ensuring only authorized parties can perform modifications
  • Enable detailed logging and continuous monitoring of API requests and data changes to detect suspicious activity

Generated by OpenCVE AI on August 2, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Advanced Pricing

Mon, 27 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leading to Data Breach in Oracle Advanced Pricing
Weaknesses CWE-200
CWE-285

Sun, 26 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leading to Data Breach in Oracle Advanced Pricing
Weaknesses CWE-200
CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle advanced Pricing
CPEs cpe:2.3:a:oracle:advanced_pricing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Pricing
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Advanced Pricing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:47.802Z

Reserved: 2026-07-08T15:51:55.597Z

Link: CVE-2026-60870

cve-icon Vulnrichment

Updated: 2026-07-24T17:42:55.435Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:23.910

Modified: 2026-07-29T05:16:56.500

Link: CVE-2026-60870

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:45:05Z

Weaknesses