Description
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw exists in the Internal Operations component of Oracle Public Sector Financials, part of Oracle E‑Business Suite. It allows a low‑privileged attacker with network access over HTTP to read a small subset of data that the application exposes. The vulnerability leads to a confidentiality breach, giving attackers unauthorized access to sensitive business information.

Affected Systems

Oracle Public Sector Financials, within Oracle E‑Business Suite, is affected in releases 12.2.3 through 12.2.15. These are the only versions known to contain the flaw.

Risk and Exploitability

The CVSS base score of 3.1 indicates low severity, and the EPSS score of less than 1 % reflects a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to reach the system over HTTP and to have low‑privilege credentials, making successful attacks unlikely but still possible for adversaries who obtain legitimate network access.

Generated by OpenCVE AI on August 4, 2026 at 02:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Public Sector Financials to a patched release that addresses this issue, preferably a version newer than 12.2.15.
  • Ensure that inbound HTTP traffic to the Public Sector Financials appliance is restricted to trusted networks, internal users, or VPN connections, blocking arbitrary external hosts.
  • Implement strong access control policies inside the application, verifying that users can only read data they are authorized to view, thereby mitigating the impact of any residual disclosure vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Disclosure via HTTP in Oracle Public Sector Financials

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Low Severity Unauthorized Data Disclosure via HTTP in Oracle Public Sector Financials Unauthorized Data Disclosure via HTTP in Oracle Public Sector Financials

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low Severity Unauthorized Data Disclosure via HTTP in Oracle Public Sector Financials

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Public Sector Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:52:27.200Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60930

cve-icon Vulnrichment

Updated: 2026-07-24T16:52:16.233Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:28.000

Modified: 2026-07-29T15:59:24.583

Link: CVE-2026-60930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor