Description
Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Optimization. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Optimization. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Inventory Optimization user interface permits an attacker who has a low‑privileged account and network reach to send specially crafted HTTP requests that can cause a partial denial of service. The weakness is a flaw in resource handling (CWE‑400) and is limited to availability; confidentiality and integrity are not affected.

Affected Systems

Oracle Inventory Optimization versions 12.2.3 through 12.2.15, specifically the User Interface component, are affected. Systems that expose this web UI to network traffic are at risk, while installations that have the UI isolated or disabled are not impacted.

Risk and Exploitability

The CVSS base score of 3.1 and an EPSS score of less than 1 % suggest a low likelihood of real‑world exploitation. The attack requires network connectivity to the UI and a low‑privileged account, making it hard to achieve. The resulting partial denial of service may degrade service continuity but is unlikely to cause immediate critical disruption.

Generated by OpenCVE AI on August 5, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict Network Access to the Inventory Optimization UI using firewalls or VPNs to limit exposure to trusted users and networks.
  • Configure a web application firewall or rate limiting on the web server hosting the UI to detect and block anomalous or excessive HTTP requests.
  • Monitor the web server logs for abnormal request patterns targeting the affected UI and investigate any identified anomalies promptly.

Generated by OpenCVE AI on August 5, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via Unauthorized HTTP Requests in Oracle Inventory Optimization UI

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via Unauthorized HTTP Requests in Oracle Inventory Optimization UI

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service in Oracle Inventory Optimization via HTTP
Weaknesses CWE-399

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service in Oracle Inventory Optimization via HTTP
Weaknesses CWE-399

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Optimization. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Optimization. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle inventory Optimization
CPEs cpe:2.3:a:oracle:inventory_optimization:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle inventory Optimization
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Inventory Optimization
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:39:47.708Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61048

cve-icon Vulnrichment

Updated: 2026-07-24T14:39:38.209Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption