Description
Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Landed Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Landed Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Landed Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Landed Cost Management allows a low privileged attacker who can reach the system over HTTP to compromise the application. Successful exploitation allows the attacker to create, delete, or modify critical data, or even gain unrestricted access to all data managed by the system. The flaw carries severe confidentiality and integrity impacts, as reflected in the CVSS 3.1 scoring of 8.1 with a network attack vector, low attack complexity, low privileges, and no user interaction.

Affected Systems

Oracle Landed Cost Management, part of Oracle E‑Business Suite (Internal Operations), is affected for all supported releases from 12.2.3 through 12.2.15. Users of these versions should verify their installed revision and apply any Oracle‑released fixes.

Risk and Exploitability

The high CVSS score indicates a serious threat, yet the EPSS calculation of less than 1% shows a low current likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but its availability and the fact that it can be triggered by a low‑privileged network user make it dangerous in environments where HTTP access is permitted without strong network segmentation or authentication controls. Attackers, once accessing the network, can exploit this flaw without requiring privileged credentials or interacting with a user to achieve persistent data loss or unauthorized disclosure.

Generated by OpenCVE AI on August 5, 2026 at 01:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Security Patch released in the CPU July 2026 advisory.
  • Restrict HTTP traffic to the Landed Cost Management application to trusted internal networks or require VPN access.
  • Enforce strict role‑based access controls and audit logs to detect unauthorized data changes.

Generated by OpenCVE AI on August 5, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploitation in Oracle Landed Cost Management Allows Unauthorized Data Modification
Weaknesses CWE-200
CWE-284

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploitation in Oracle Landed Cost Management Allows Unauthorized Data Modification
Weaknesses CWE-284

Thu, 30 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploitation in Oracle Landed Cost Management Allows Unauthorized Data Modification
Weaknesses CWE-284

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Access Enables Unauthorized Data Modification in Oracle Landed Cost Management
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Access Enables Unauthorized Data Modification in Oracle Landed Cost Management
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Landed Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Landed Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Landed Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Landed Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle landed Cost Management
CPEs cpe:2.3:a:oracle:landed_cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle landed Cost Management
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Landed Cost Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:11:12.861Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-61004

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control