Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Work in Process, part of Oracle E-Business Suite, allows an attacker with low privileges and network access via HTTP to read sensitive data. The flaw does not enable code execution or disruption of service but does expose critical information, resulting in confidentiality loss. The CVSS 3.1 base score of 5.3 reflects this selective compromise, with the attack vector limited to network access and requiring high complexity to exploit.

Affected Systems

The issue affects Oracle Work in Process versions 12.2.3 through 12.2.15. Any deployment of this product that remains at or below version 12.2.15 and exposes the internal operations component over HTTP is subject to the risk.

Risk and Exploitability

The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attacker needs only network connectivity to the affected HTTP interface and a low‑privilege account, making it relatively accessible in environments lacking strict access controls. Exfiltration of data could occur without detection if logging is insufficient.

Generated by OpenCVE AI on August 2, 2026 at 20:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Work in Process to a version newer than 12.2.15 or apply the vendor patch issued by Oracle.
  • Restrict HTTP access by implementing firewall rules or network segmentation so that only trusted IP addresses can reach the internal operations component.
  • Enable comprehensive logging for all data read attempts and regularly review logs for anomalous activity.

Generated by OpenCVE AI on August 2, 2026 at 20:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP in Oracle Work in Process

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP in Oracle Work in Process

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Oracle Work in Process Unauthorized Data Access Vulnerability
Weaknesses CWE-284

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Work in Process Unauthorized Data Access Vulnerability
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:36:09.147Z

Reserved: 2026-07-08T15:51:55.599Z

Link: CVE-2026-60888

cve-icon Vulnrichment

Updated: 2026-07-24T17:36:01.035Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:24.700

Modified: 2026-07-28T19:46:01.073

Link: CVE-2026-60888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor