Description
Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Risk Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Risk Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Risk Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an authorization bypass that allows an attacker with only a low‑privileged account and network access to the Oracle Risk Management HTTP service to create, modify, delete, and read data that should be protected. The flaw results in a high confidentiality and integrity impact, reflected in the CVSS 3.1 base score of 8.1. It does not provide a path for remote code execution or denial of service, but it effectively removes all access controls for the affected data.

Affected Systems

Oracle Corporation’s Oracle Risk Management component of Oracle E‑Business Suite is affected. All supported releases from 12.2.3 through 12.2.15 contain the flaw. Users should verify the minor release they are running and contact Oracle for the appropriate fix or upgrade path.

Risk and Exploitability

The high CVSS score indicates a severe problem, and the EPSS score of less than 1% suggests that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Attackers need only remote HTTP connectivity and a legitimate but low‑privileged user credential to exploit the defect, giving them the ability to read all accessible data and modify or delete any critical information. Due to the clear impact on confidentiality and integrity, the flaw should be treated as a high‑risk issue that can be leveraged to compromise entire data sets within the susceptible application.

Generated by OpenCVE AI on August 5, 2026 at 02:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a version that contains the fix for the authorization bypass – consult Oracle’s official advisories for the appropriate patch or upgrade path.
  • Restrict network access to the Oracle Risk Management HTTP endpoint by allowing traffic only from trusted hosts or by placing the application behind a firewall or VPN.
  • Implement comprehensive audit logging for all data creation, modification, and deletion events and review the logs regularly for indications of unauthorized activity.

Generated by OpenCVE AI on August 5, 2026 at 02:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Oracle Risk Management Authorization Bypass Allowing Unauthorized Data Access
Weaknesses CWE-284

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle Risk Management Allows Unauthorized Data Access
Weaknesses CWE-284

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle Risk Management Allows Unauthorized Data Access
Weaknesses CWE-284

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Risk Management via Low Privilege HTTP Abuse
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Risk Management via Low Privilege HTTP Abuse
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Risk Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Risk Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Risk Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle risk Management
CPEs cpe:2.3:a:oracle:risk_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle risk Management
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle E-business Suite Risk Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:42:14.933Z

Reserved: 2026-07-08T15:51:55.597Z

Link: CVE-2026-60871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:24.020

Modified: 2026-08-06T15:27:09.443

Link: CVE-2026-60871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:45:17Z

Weaknesses