Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Work in Process. CVSS 3.1 Base Score 3.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).
Published: 2026-07-21
Score: 3.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Work in Process component is vulnerable to a local privilege issue that allows an authenticated user with low privileges to read a limited set of data exposed by the product and to trigger a partial denial of service. The weakness is consistent with CWE‑200 information disclosure and CWE‑404 missing error handling. The exploit does not grant system‑wide control but can manifest a modest confidentiality breach and an availability disruption within the application.

Affected Systems

Oracle Work in Process, part of Oracle E‑Business Suite’s Internal Operations component, is affected in version ranges 12.2.3 through 12.2.15 released by Oracle Corporation. The product runs on infrastructure where users have local access, and the vulnerability is confined to that installation.

Risk and Exploitability

The CVSS v3.1 base score of 3.6 reflects modest confidentiality and availability impact, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. Exploitability requires local or low‑privileged logon to the host running Oracle Work in Process, so it is not remotely exploitable. The attack enables only read access to a subset of data and a limited service interruption, and it does not provide elevation to higher privileges or full system compromise. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 2, 2026 at 20:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch that addresses CVE‑2026‑60896 on all affected servers.
  • Restrict local logon privileges on the host running Oracle Work in Process to only authorized personnel.
  • Enable and review detailed auditing for data access and service restarts to detect any unauthorized activity.
  • Consider network segmentation or container isolation to limit the product’s exposure to the broader infrastructure.

Generated by OpenCVE AI on August 2, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit Allows Unauthorized Data Read and Partial Service Disruption in Oracle Work in Process

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Read Access and Partial Denial of Service in Oracle Work in Process
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-404
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Read Access and Partial Denial of Service in Oracle Work in Process
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Work in Process. CVSS 3.1 Base Score 3.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:21:18.533Z

Reserved: 2026-07-08T15:51:55.600Z

Link: CVE-2026-60896

cve-icon Vulnrichment

Updated: 2026-07-24T17:21:12.749Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-404

    Improper Resource Shutdown or Release