Description
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Internal Operations component of Oracle Public Sector Financials allows an attacker with a low‑privileged account and network access via HTTP to modify, insert, or delete data. The vulnerability does not directly compromise confidentiality or availability; it grants unauthorized data manipulation with an integrity impact reflected in the CVSS base score of 3.1.

Affected Systems

Oracle Public Sector Financials versions 12.2.3 through 12.2.15, part of Oracle E‑Business Suite, are vulnerable. The issue exists when this package is deployed and accessed over HTTP.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity, while the EPSS score of less than 1 % suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged account and HTTP network access; the description notes it is difficult to exploit, implying that a successful attack would entail careful enumeration of the application’s internal operations and possibly bypassing authentication controls.

Generated by OpenCVE AI on August 5, 2026 at 01:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Public Sector Financials patch or upgrade beyond version 12.2.15.
  • Restrict HTTP access to the application to trusted hosts, networks, or VPNs to limit exposure.
  • Enforce strict authorization controls for database operations to prevent low‑privileged data manipulation.
  • Monitor database and application logs for abnormal write activity to detect potential misuse.

Generated by OpenCVE AI on August 5, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Oracle Public Sector Financials: Low-Privilege Data Modification via HTTP

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Data Modification in Oracle Public Sector Financials

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Data Modification in Oracle Public Sector Financials

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Public Sector Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:02:59.056Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60929

cve-icon Vulnrichment

Updated: 2026-07-24T17:02:53.217Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:27.893

Modified: 2026-07-29T15:55:27.957

Link: CVE-2026-60929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses