Description
Vulnerability in the Oracle Financials Common Country product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Country. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Country accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials Common Country accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Financials Common Country product of Oracle E‑Business Suite includes an Internal Operations component that is vulnerable to an improper authorization flaw. A low‑privileged attacker who can reach the component over HTTP can craft requests to create, delete, or modify critical data, effectively gaining unauthorized data access or complete control over all Country data. The weakness results in severe confidentiality and integrity impacts, aligning with CWE‑284.

Affected Systems

Oracle Corporation’s Oracle Financials Common Country, part of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 are vulnerable. No patch or upgrade notice is included in the data, so installations within this range remain at risk until remedial action is applied.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high‑severity flaw that can be exploited remotely. The EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based HTTP access to the Internal Operations component, where a low‑privileged attacker can send crafted requests to gain unauthorized data access or manipulation.

Generated by OpenCVE AI on August 4, 2026 at 16:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle patch or upgrade to a release that contains the fix for Oracle Financials Common Country.
  • Restrict network access to the Internal Operations component via firewall rules or VPN, limiting exposure to authorized administrators only.
  • Disable or remove HTTP access to the vulnerable component if it is not required for operational purposes.
  • Continuously monitor audit logs for unauthorized data modification attempts or abnormal activity around the Country module.

Generated by OpenCVE AI on August 4, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Financials Common Country Allows Unauthorized Data Modification

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Financials Common Country Allows Unauthorized Data Modification

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Lets Attackers Alter Oracle Financials Common Country Data

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Lets Attackers Alter Oracle Financials Common Country Data
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Financials Common Country product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Country. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Country accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials Common Country accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle financials Common Country
CPEs cpe:2.3:a:oracle:financials_common_country:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle financials Common Country
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle E-business Suite Financials Common Country
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:42:00.655Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61031

cve-icon Vulnrichment

Updated: 2026-07-24T14:41:55.808Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:34.490

Modified: 2026-08-04T16:57:00.920

Link: CVE-2026-61031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses