Description
Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. While the vulnerability is in Oracle Service Fulfillment Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw in the Fulfillment Engine of Oracle Service Fulfillment Manager that allows a high‑privileged attacker who can reach the system over HTTP to create, delete, or modify critical data, or obtain complete read access to all data exposed by the application. The flaw is reflected in a CVSS 3.1 base score of 8.7, indicating significant confidentiality and integrity impact, and its scope signals that an attacker could affect services beyond the Service Fulfillment Manager itself.

Affected Systems

Oracle Service Fulfillment Manager, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are vulnerable. Deployments that expose the HTTP interface to an internal or external network are at risk, and the scope change means that any applications or services that rely on the Fulfillment Engine for data provisioning could also be adversely impacted.

Risk and Exploitability

The high CVSS score signals a serious threat, while the EPSS score of less than 1% suggests a low probability of active exploitation and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker accessing the exposed HTTP interface, which requires that the attacker already possess high‑privilege credentials or gains them via other means. No public exploit is currently known, but the scope change and privileged nature of the attack could result in extensive data compromise if the vulnerability is used.

Generated by OpenCVE AI on August 2, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU Jul 2026 maintenance release that contains the fix for Service Fulfillment Manager.
  • Restrict inbound HTTP traffic to the Service Fulfillment Manager to trusted networks or a VPN tunnel, thereby limiting exposure to external actors.
  • Enforce strong authentication for privileged accounts, enable multi‑factor authentication, and monitor for anomalous activity.

Generated by OpenCVE AI on August 2, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allowing High‑Privileged Data Manipulation in Oracle Service Fulfillment Manager

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title High Privilege Unauthorized Data Manipulation via HTTP in Oracle Service Fulfillment Manager
Weaknesses CWE-285

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title High Privilege Unauthorized Data Manipulation via HTTP in Oracle Service Fulfillment Manager
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. While the vulnerability is in Oracle Service Fulfillment Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle service Fulfillment Manager
CPEs cpe:2.3:a:oracle:service_fulfillment_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Fulfillment Manager
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Service Fulfillment Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:49:13.890Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60941

cve-icon Vulnrichment

Updated: 2026-07-24T16:49:07.629Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:28.900

Modified: 2026-07-24T17:17:32.590

Link: CVE-2026-60941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control