Description
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Learning Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Learning Management accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Learning Management permits a network attacker with low privileges, using HTTP, to gain unauthorized create, delete or modify rights over critical data. The vulnerability requires the victim to perform a separate action, indicating user interaction is needed. A successful exploit would compromise the confidentiality and integrity of all data stored in the Learning Management system, while availability remains unaffected. The weakness involves an insecure redirect component (CWE‑601) in addition to improper authorization (CWE‑284).

Affected Systems

Products affected include Oracle Learning Management within Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15. These versions expose an internal operations component that is vulnerable to the described attack. Versions beyond 12.2.15 are not listed as affected, but administrators should verify patch status.

Risk and Exploitability

The CVSS 3.1 base score of 7.3 signals a high impact, with a high confidentiality and integrity loss. The EPSS score is under 1%, implying the publicized exploitation probability is very low, yet the vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires only basic network access and low privilege, making it attractive for attackers that can lure a victim to provide the required interaction.

Generated by OpenCVE AI on August 2, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install any Oracle Learning Management update that addresses CVE-2026-60945, such as the patches released in the July 2026 CPU.
  • Restrict HTTP access to Oracle Learning Management by firewall rules or VPN, enforcing strong authentication so that only trusted users can reach the affected component.
  • Enable and regularly review audit logging to detect unauthorized create, delete or modify attempts and promptly investigate anomalies.

Generated by OpenCVE AI on August 2, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Unauthorized Data Modification in Oracle Learning Management

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Modification Vulnerability in Oracle Learning Management (HTTP)
Weaknesses CWE-639

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Modification Vulnerability in Oracle Learning Management (HTTP)
Weaknesses CWE-284
CWE-639

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Learning Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Learning Management accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle learning Management
CPEs cpe:2.3:a:oracle:learning_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle learning Management
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Learning Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:45:38.053Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60945

cve-icon Vulnrichment

Updated: 2026-07-24T16:45:30.845Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:29.263

Modified: 2026-07-29T16:51:18.847

Link: CVE-2026-60945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')