Description
Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Management. CVSS 3.1 Base Score 1.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Inventory Management has a low‑severity flaw that allows a high‑privileged user who can log on to the host to compromise the application and trigger a partial denial of service. The weakness – an improper error handling issue (CWE‑404) – can affect the Availability of the Inventory Management component alone, with no impact on data confidentiality or integrity.

Affected Systems

The flaw affects Oracle E‑Business Suite Oracle Inventory Management versions 12.2.3 through 12.2.15. It is local; the attacker must have privileged access on the infrastructure where the product runs.

Risk and Exploitability

The CVSS 3.1 base score of 1.9 reflects a low availability impact with a local access vector, high attack complexity, and high privileges required. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Only users who already possess privileged access could exploit this flaw, so the risk is confined to environments where such access exists.

Generated by OpenCVE AI on August 4, 2026 at 02:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle E‑Business Suite patch that addresses Inventory Management.
  • Limit local privileged access to the server hosting Inventory Management and enforce least privilege and separation of duties.
  • Monitor application and system logs for signs of abnormal behavior or denial‑of‑service attempts; investigate suspicious events.
  • If no patch is available, consider disabling or removing the Inventory Management component until a fix is released.
  • Stay current with Oracle security advisories and apply subsequent updates promptly.

Generated by OpenCVE AI on August 4, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Privileged Attacker Can Induce Partial Denial of Service in Oracle Inventory Management

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Oracle Inventory Management Partial Denial of Service Vulnerability
Weaknesses CWE-284
CWE-639

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Inventory Management Partial Denial of Service Vulnerability
Weaknesses CWE-284
CWE-639

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes to compromise Oracle Inventory Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Management. CVSS 3.1 Base Score 1.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle inventory Management
CPEs cpe:2.3:a:oracle:inventory_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle inventory Management
References
Metrics cvssV3_1

{'score': 1.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Inventory Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:49:28.227Z

Reserved: 2026-07-08T15:51:55.608Z

Link: CVE-2026-61028

cve-icon Vulnrichment

Updated: 2026-07-24T14:49:21.921Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:34.257

Modified: 2026-08-04T17:07:12.567

Link: CVE-2026-61028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release