Description
Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Supply Chain Planning. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Supply Chain Planning. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Advanced Supply Chain Planning is a high‑privilege access flaw that can be exploited by an attacker who has network reach to the service via HTTP. Once the flaw is leveraged, the attacker can gain full control of the application, effectively taking it over. This is a CWE‑284 weakness, indicating a failure to restrict access to privileged resources. Successful exploitation compromises confidentiality, integrity, and availability, allowing the attacker to read, modify, or delete data and interrupt service operations.

Affected Systems

The affected product is Oracle Advanced Supply Chain Planning, part of Oracle E‑Business Suite, component Core. Vulnerable releases span versions 12.2.3 through 12.2.15. The issue is specific to Oracle Corporation’s implementation and is documented in the July 2026 CPU advisory.

Risk and Exploitability

The base CVSS score is 7.2, indicating a high severity. The EPSS score is below 1%, suggesting a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network access to the HTTP interface and the ability to authenticate with high‑privilege credentials, implying that the threat is limited to environments where such access exists. If exploited, an attacker can achieve a full application takeover.

Generated by OpenCVE AI on August 2, 2026 at 20:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the July 2026 Critical Patch Update for Oracle Advanced Supply Chain Planning from the Oracle CPU site.
  • Configure the application environment to limit HTTP traffic to trusted IP ranges or subnet blocks using firewall rules or ACLs.
  • Disable or tightly restrict any unused administrative interfaces or third‑party integrations that expose the HTTP service to reduce the attack surface.

Generated by OpenCVE AI on August 2, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title High Privilege Access via HTTP Exploit in Oracle Advanced Supply Chain Planning

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle Advanced Supply Chain Planning
Weaknesses CWE-287

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in Oracle Advanced Supply Chain Planning
Weaknesses CWE-287

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Supply Chain Planning. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Supply Chain Planning. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle advanced Supply Chain Planning
CPEs cpe:2.3:a:oracle:advanced_supply_chain_planning:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Supply Chain Planning
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Advanced Supply Chain Planning
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:49.340Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61039

cve-icon Vulnrichment

Updated: 2026-07-24T14:44:32.692Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses