Description
Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data as well as unauthorized access to critical data or complete access to all Oracle Loans accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Loans allows a low‑privileged attacker who can reach the application over HTTP to create, delete or modify user data, or to read all data available to the Loans system. The impact includes significant confidentiality and integrity loss for critical data and potentially full access to the Loans database. This weakness aligns with improper access control deficiencies such as CWE‑284.

Affected Systems

Oracle Loans, version 12.2.3 through 12.2.15, part of Oracle E‑Business Suite Internal Operations. Administrators should verify which release they run and whether it matches the affected range.

Risk and Exploitability

The CVSS 3.1 base score is 8.1, indicating high overall risk. The EPSS score is below 1%, suggesting a very low current exploitation probability, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote over the network via HTTP, and the attacker requires only low privileges on the networked interface to exploit this weakness. The existence of this flaw means that any exposed instance of Oracle Loans could be compromised, allowing unauthorized and privileged data access.

Generated by OpenCVE AI on August 4, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Oracle Loans
  • Restrict inbound network traffic to the Loans service by using firewall rules or VPN segmentation
  • Enforce least‑privilege role assignments and validate access controls within Oracle Loans

Generated by OpenCVE AI on August 4, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Loans through Low-Privilege HTTP Exploit

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Loans through Low-Privilege HTTP Exploit

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploitation of Oracle Loans Allows Unauthorized Data Access
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploitation of Oracle Loans Allows Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data as well as unauthorized access to critical data or complete access to all Oracle Loans accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle loans
CPEs cpe:2.3:a:oracle:loans:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle loans
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:45:34.109Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61037

cve-icon Vulnrichment

Updated: 2026-07-24T14:45:27.592Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses