Description
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in takeover of Oracle Inventory Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Inventory Management’s Internal Operations component contains a flaw that can be exploited by a high‑privileged user who can log onto the host where the application runs. Successful exploitation provides the attacker with the ability to take over the application, compromising confidentiality, integrity, and availability of inventory data and control functions. The weakness is the granting of elevation of privilege (CWE‑269).

Affected Systems

Oracle Inventory Management for Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected.

Risk and Exploitability

The CVSS 3.1 Base Score of 6.4 indicates moderate severity. Attack requires local access and high privileges, which reduces the likelihood of exploitation. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, so no current evidence of exploitation exists. Nevertheless, environments that already have high‑privileged local accounts standing in contact with the Oracle Inventory Management servers remain at risk.

Generated by OpenCVE AI on August 4, 2026 at 02:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Inventory Management to version 12.2.16 or later, or apply the vendor‑issued security patch for this vulnerability.
  • Limit or remove high‑privileged local accounts that have direct access to Oracle Inventory Management servers.
  • Enforce the principle of least privilege on all system accounts that run Oracle Inventory Management.
  • Monitor audit logs for anomalous activity that could indicate exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 02:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Inventory Management Allowing Takeover

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Oracle Inventory Management Local Privilege Escalation Vulnerability
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Inventory Management Local Privilege Escalation Vulnerability
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in takeover of Oracle Inventory Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle inventory Management
CPEs cpe:2.3:a:oracle:inventory_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle inventory Management
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Inventory Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:58:34.818Z

Reserved: 2026-07-08T15:51:55.608Z

Link: CVE-2026-61023

cve-icon Vulnrichment

Updated: 2026-07-24T14:58:22.729Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management