Description
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Time and Labor of Oracle E‑Business Suite is affected by a flaw in the Internal Operations component. A low‑privileged attacker with network access via HTTP can exploit the vulnerability to create, delete or modify critical data. Successful exploitation would grant the attacker unauthorized access to sensitive information and potentially full control of all data exposed through the Time and Labor application.

Affected Systems

Supported affected releases span Oracle Time and Labor versions 12.2.3 through 12.2.15. These versions are impacted by a flaw that can be remedied by applying the Oracle Security Patch released in the July 2026 security alerts. Installations running within this version range should upgrade to the patched release.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates high confidentiality and integrity impact. The EPSS score of less than 1% suggests a low overall likelihood of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Attackers appear to need only a low‑privileged authenticated session with HTTP access; no elevated rights are required to trigger the malicious behavior.

Generated by OpenCVE AI on August 2, 2026 at 20:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Security Patch for CVE‑2026‑60951, available from Oracle’s security alerts for July 2026.
  • Restrict HTTP access to the Oracle Time and Labor application to trusted IP ranges and enforce strong authentication for all users.
  • Review and enforce role‑based access controls to limit modification privileges to essential personnel only.
  • If a patch is not immediately available, consider disabling the affected Internal Operations functionality until the vulnerability can be addressed.

Generated by OpenCVE AI on August 2, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged Access in Oracle Time and Labor Allows Unauthorized Data Modification

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Oracle Time and Labor: Unauthorized Data Modification via Low‑Privilege HTTP Attack
Weaknesses CWE-20
CWE-89

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Time and Labor: Unauthorized Data Modification via Low‑Privilege HTTP Attack
Weaknesses CWE-20
CWE-89

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle time And Labor
CPEs cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle time And Labor
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Time And Labor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:42:41.953Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60951

cve-icon Vulnrichment

Updated: 2026-07-24T16:42:35.707Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:29.600

Modified: 2026-07-29T16:03:15.450

Link: CVE-2026-60951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:04Z

Weaknesses