Description
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle iSupplier Portal, part of the Internal Operations component of Oracle E‑Business Suite, allows an unauthenticated attacker who can reach the system over HTTP to read a limited set of information that should otherwise be protected. This is a CWE‑200 information disclosure flaw. The vulnerability does not facilitate control, privilege escalation, or denial of service; it only permits read access to certain data.

Affected Systems

Vulnerable instances include Oracle Corporation's Oracle iSupplier Portal versions 12.2.3 through 12.2.15. Any deployment of this product within that range is exposed; newer releases are not listed as affected.

Risk and Exploitability

With a CVSS 3.1 base score of 3.7, the vulnerability carries low severity, reflecting modest confidentiality impact. The EPSS score is under 1%, indicating a very small exploitation probability at the moment of reporting, and it is not referenced in the CISA KEV catalog. The attack vector is inferred to require network connectivity to the HTTP interface of the portal, and the vulnerability can be triggered without authentication, making it accessible to any network‑present adversary.

Generated by OpenCVE AI on August 4, 2026 at 16:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether your Oracle iSupplier Portal installation falls within the affected version range (12.2.3–12.2.15); if so, consult Oracle’s CPU July 2026 alert for the official fix or upgrade path.
  • Apply the vendor‑supplied patch or upgrade to a non‑affected release to eliminate the unauthenticated read ability.
  • Restrict inbound traffic to the portal’s HTTP endpoint, or enforce authentication before allowing access to protected resources, to reduce exposure to unauthenticated users.

Generated by OpenCVE AI on August 4, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Information Disclosure in Oracle iSupplier Portal

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Information Disclosure in Oracle iSupplier Portal

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Read in Oracle iSupplier Portal

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Read in Oracle iSupplier Portal
Weaknesses CWE-200

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle isupplier Portal
CPEs cpe:2.3:a:oracle:isupplier_portal:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isupplier Portal
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Isupplier Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:13:52.481Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60919

cve-icon Vulnrichment

Updated: 2026-07-24T17:13:46.135Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:45:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor