Description
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Labor Distribution allows an attacker with low privileges who can access the system over HTTP to perform unauthorized updates, inserts, or deletions of data. The vulnerability is rated a CVSS Base Score of 3.1, indicating an impact limited to integrity with no confidentiality or availability effects reported. The weakness permits an attacker to alter business data within the application without proper authorization, potentially leading to accounting inaccuracies or trust issues.

Affected Systems

The affected product is Oracle Corporation’s Oracle Labor Distribution component of Oracle E‑Business Suite, specifically the Internal Operations module. Versions 12.2.3 through 12.2.15 are impacted. Users running any of these releases should verify whether a later, secure version is available.

Risk and Exploitability

The CVSS score of 3.1 classifies the risk as low, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is HTTP network access to the Oracle Labor Distribution interface; an attacker would need only low privileges, such as an ordinary user account to exploit the flaw.

Generated by OpenCVE AI on August 4, 2026 at 02:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the CPU July 2026 security patch for Oracle Labor Distribution as detailed by Oracle’s advisory.
  • Restrict HTTP access to the Labor Distribution instance so that only trusted internal hosts can connect, for example by configuring firewalls or network ACLs.
  • Enforce strict database write permissions so that only authorized service accounts can modify critical tables, and monitor audit logs for unexpected write operations.

Generated by OpenCVE AI on August 4, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Low‑Privilege Data Modification in Oracle Labor Distribution via HTTP

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Low‑Privilege Data Modification in Oracle Labor Distribution via HTTP

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege HTTP Access in Oracle Labor Distribution

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege HTTP Access in Oracle Labor Distribution
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle labor Distribution
CPEs cpe:2.3:a:oracle:labor_distribution:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle labor Distribution
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle E-business Suite Labor Distribution
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:54:25.025Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60937

cve-icon Vulnrichment

Updated: 2026-07-24T16:54:19.736Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:28.440

Modified: 2026-07-29T17:09:59.503

Link: CVE-2026-60937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses