Description
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Installed Base accessible data as well as unauthorized read access to a subset of Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Installed Base’s Create Item Instance component allows an attacker with low privilege and network access via HTTP to read, update, insert, or delete data that should be protected, or to trigger a partial denial of service. If successfully exploited the attacker could modify application data, exfiltrate sensitive information, or disrupt service availability. The weakness is a failure of proper access control, allowing unauthorized operations on database records and causing limited interruption to service normality.

Affected Systems

Oracle E-Business Suite users running Oracle Installed Base versions from 12.2.4 through 12.2.15 are affected. The vulnerability is present only in the Create Item Instance component of these releases.

Risk and Exploitability

The CVSS 3.1 base score of 5.0 reflects moderate risk, with a low exploitation probability indicated by an EPSS score of less than 1%. The attack vector is likely network‑based over HTTP and requires a low‑privileged account. The vulnerability is not currently listed in the CISA KEV catalog. Due to the low surface and high access requirement, exploitation is considered difficult, but the potential for unauthorized data manipulation and service disruption warrants attention.

Generated by OpenCVE AI on August 2, 2026 at 20:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Installed Base to a patched version that resolves the flaw
  • Configure firewall rules or access controls to restrict HTTP access to the Oracle Installed Base only to trusted internal hosts
  • Enable logging and audit trails for data modification and service status, and review logs regularly for anomalous activity

Generated by OpenCVE AI on August 2, 2026 at 20:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via HTTP in Oracle Installed Base

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Attack Allows Data Manipulation and Partial Denial in Oracle Installed Base
Weaknesses CWE-264

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Attack Allows Data Manipulation and Partial Denial in Oracle Installed Base
Weaknesses CWE-264

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Installed Base accessible data as well as unauthorized read access to a subset of Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle installed Base
CPEs cpe:2.3:a:oracle:installed_base:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle installed Base
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Installed Base
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:14:56.452Z

Reserved: 2026-07-08T15:51:55.601Z

Link: CVE-2026-60907

cve-icon Vulnrichment

Updated: 2026-07-24T17:14:41.803Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:45:05Z

Weaknesses