Description
Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Service Fulfillment Manager’s Fulfillment Engine permits a low‑privileged attacker who can reach the service over HTTP to create, delete, or modify critical data, or to gain unauthorized access to all data stored by the application. This results in substantial confidentiality and integrity loss.

Affected Systems

Oracle Service Fulfillment Manager, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The product is impacted when the component termed Fulfillment Engine is present.

Risk and Exploitability

The CVSS v3.1 base score is 8.1, indicating high severity. The EPSS score is less than 1 %, so widespread exploitation is unlikely, and the vulnerability is not cataloged in CISA’s KEV list. Nevertheless, an attacker who can reach the HTTP interface with low privileges can exploit the flaw, requiring only normal network access and resulting in unauthorized creation or deletion of data. The vulnerability remains a significant risk for organizations that have left the service exposed to untrusted networks.

Generated by OpenCVE AI on August 4, 2026 at 02:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that resolves CVE‑2026‑60942, following the update documentation in the 2026‑Jul CPU statement.
  • Limit HTTP access to Oracle Service Fulfillment Manager to trusted IP ranges or use a VPN, and configure firewall rules to block unsolicited traffic.
  • Enforce strict account controls by removing default or unused accounts and ensuring all service accounts run with the minimum privileges required. Document these changes in an access control policy.
  • Monitor access logs for anomalous activity and set alerts for unexpected read or write operations on critical data.

Generated by OpenCVE AI on August 4, 2026 at 02:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Modification in Oracle Service Fulfillment Manager via HTTP

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Modification in Oracle Service Fulfillment Manager via HTTP

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Access Allows Unauthorized Data Modification in Oracle Service Fulfillment Manager
Weaknesses CWE-269

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Access Allows Unauthorized Data Modification in Oracle Service Fulfillment Manager
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle service Fulfillment Manager
CPEs cpe:2.3:a:oracle:service_fulfillment_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Fulfillment Manager
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Service Fulfillment Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:47:18.072Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60942

cve-icon Vulnrichment

Updated: 2026-07-24T16:47:12.031Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses