Description
Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Contracts accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Contracts accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle Service Contracts (Internal Operations component) permits an attacker with high privileged credentials and network access via HTTP to create, delete, or modify critical data. The flaw is a CWE-284 Improper Access Control, with a CVSS 3.1 base score of 5.7, driven by confidentiality and integrity impacts, and requires human interaction from a user other than the attacker to succeed. The effect is unauthorized alteration of data or complete access to all Oracle Service Contracts data accessible to the victim.

Affected Systems

The affected product is Oracle Service Contracts, part of Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 are vulnerable. No other vendor or product is listed.

Risk and Exploitability

The only network attack vector is via HTTP (AV:N). Attackers must have high privileges (PR:H) and high complexity (AC:H). User interaction is required (UI:R) and the scope remains unchanged (S:U). The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation seen in the field, and the vulnerability is not listed in CISA's KEV catalog. Despite the low exploitation probability, the potential impact on data confidentiality and integrity makes the vulnerability significant for environments that rely on the Oracle Service Contracts product.

Generated by OpenCVE AI on August 4, 2026 at 16:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for CVE-2026-60940, which fixes the CWE‑284 Improper Access Control flaw.
  • Restrict HTTP access to the Oracle Service Contracts service to a limited set of trusted IP addresses or implement VPN-based ingress only, mitigating the improper access control issue.
  • Enable detailed logging and regularly audit logs for unauthorized create, delete, or modify actions on Service Contracts data to detect potential CWE‑284 exploitation.

Generated by OpenCVE AI on August 4, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via High Privilege in Oracle Service Contracts

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via High Privilege in Oracle Service Contracts

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Oracle Service Contracts Unauthorized Data Modification Vulnerability
Weaknesses CWE-862

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Service Contracts Unauthorized Data Modification Vulnerability
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Contracts accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Contracts accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle service Contracts
CPEs cpe:2.3:a:oracle:service_contracts:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Contracts
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Service Contracts
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:51:16.854Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60940

cve-icon Vulnrichment

Updated: 2026-07-24T16:50:41.730Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:28.783

Modified: 2026-08-11T14:40:38.757

Link: CVE-2026-60940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:45:04Z

Weaknesses