Description
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Internal Operations component of Oracle iSupplier Portal versions 12.2.3 to 12.2.15. It is a data‑disclosure flaw (CWE‑200) that permits a low‑privileged attacker with network access via HTTP to read restricted data from the portal, compromising confidentiality while leaving integrity and availability untouched. The CVSS base score of 3.1 reflects this modest impact, with a low confidentiality effect only.

Affected Systems

Affected systems include Oracle Corporation’s iSupplier Portal product as part of Oracle E‑Business Suite, specifically the 12.2.3 to 12.2.15 release range. No other vendors or products are listed in the advisory.

Risk and Exploitability

The CVSS base score of 3.1 indicates low severity, with a low confidentiality impact and no impact on integrity or availability. The EPSS score of less than 1% points to a very low probability of exploitation. Attackers would need network access to the portal’s HTTP interface; based on the description, it is inferred that simple HTTP requests can retrieve restricted data. The high attack complexity and low privilege requirement make this a shallow threat for environments running the affected versions. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 2, 2026 at 20:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle iSupplier Portal to a version newer than 12.2.15 that contains the fix
  • Restrict portal access by configuring firewall rules or VPN limits so that only trusted hosts can reach the HTTP interface
  • Enforce role‑based access control and validate permissions for data view endpoints
  • Monitor portal access logs for anomalous read activity and enforce strict least‑privilege policies on user accounts

Generated by OpenCVE AI on August 2, 2026 at 20:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Data Disclosure in Oracle iSupplier Portal via HTTP

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low-privilege Remote Data Disclosure in Oracle iSupplier Portal
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low-privilege Remote Data Disclosure in Oracle iSupplier Portal
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle isupplier Portal
CPEs cpe:2.3:a:oracle:isupplier_portal:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isupplier Portal
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Isupplier Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:12:14.775Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60922

cve-icon Vulnrichment

Updated: 2026-07-24T17:12:08.040Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:27.250

Modified: 2026-08-06T15:28:59.023

Link: CVE-2026-60922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor