Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Work in Process, part of Oracle E‑Business Suite, allows a high‑privileged attacker who has logged onto the same infrastructure to read a subset of data that should normally be protected. The vulnerability does not give code execution or denial of service; it simply bypasses normal authorization controls, leading to a confidentiality compromise consistent with CWE‑200, Information Exposure. The CVSS 3.1 score of 1.9 and vector AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N indicate a low overall impact limited to confidentiality.

Affected Systems

Oracle Work in Process running in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 is affected. No other Oracle products or versions are listed as impacted by this CVE.

Risk and Exploitability

The attack vector is internal and local; the attacker must hold a high‑privilege account on the infrastructure where the product executes. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild, and the CVSS score of 1.9 reflects a minimal overall risk. The vulnerability is not recorded in the CISA KEV catalog. Organizations that allow privileged local users or lack strict role‑based access controls should assess the exposure and apply mitigations promptly.

Generated by OpenCVE AI on August 4, 2026 at 02:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Oracle Work in Process as released in the July 2026 CPU.
  • Restrict local administrator privileges on servers running the product and enforce least‑privilege policies.
  • Enable and monitor audit logs for attempts to read protected data, and set alerts for unauthorized data access.
  • Ensure the patch is deployed on all instances within the affected versions 12.2.3–12.2.15.

Generated by OpenCVE AI on August 4, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Information Exposure via Privileged Local Access in Oracle Work in Process

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Information Exposure via Privileged Local Access in Oracle Work in Process

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 1.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:33:33.749Z

Reserved: 2026-07-08T15:51:55.599Z

Link: CVE-2026-60891

cve-icon Vulnrichment

Updated: 2026-07-24T17:33:26.955Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor