Description
Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks of this vulnerability can result in takeover of Oracle Service Fulfillment Manager. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability: a difficult‑to‑exploit flaw in the Fulfillment Engine of Oracle Service Fulfillment Manager lets an attacker with low privilege and network connectivity over HTTP compromise the service. The weakness results from broken object level authorization (CWE‑269), allowing the attacker to execute functions beyond their intended permissions. Successful exploitation leads to full takeover, impacting confidentiality, integrity, and availability of the Service Fulfillment Manager.

Affected Systems

Oracle Service Fulfillment Manager in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected. No other products or versions are listed.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high‑severity risk, yet the EPSS score of less than 1% suggests the likelihood of exploitation in the wild is low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request from a low‑privileged user; local or elevated privileges are not required.

Generated by OpenCVE AI on August 4, 2026 at 16:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's official patch or upgrade to a version newer than 12.2.15.
  • Restrict HTTP access to the Service Fulfillment Manager to trusted networks or block unnecessary inbound connections.
  • Monitor audit logs for suspicious activity involving the Fulfillment Engine and investigate any anomalies promptly.

Generated by OpenCVE AI on August 4, 2026 at 16:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote HTTP Takeover in Oracle Service Fulfillment Manager

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote HTTP Takeover in Oracle Service Fulfillment Manager
Weaknesses CWE-284

Mon, 27 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Low Privilege, Network Exploitable HTTP Vulnerability in Oracle Service Fulfillment Manager Leading to Takeover

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privilege, Network Exploitable HTTP Vulnerability in Oracle Service Fulfillment Manager Leading to Takeover
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks of this vulnerability can result in takeover of Oracle Service Fulfillment Manager. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Fulfillment Manager
CPEs cpe:2.3:a:oracle:service_fulfillment_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Fulfillment Manager
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Fulfillment Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:46:28.884Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60943

cve-icon Vulnrichment

Updated: 2026-07-24T16:46:23.523Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:45:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management