Description
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Concurrent Processing accessible data as well as unauthorized read access to a subset of Oracle Concurrent Processing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Concurrent Processing. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker with low privileges and network access via HTTP to exploit a missing access control check to update, insert, or delete data, read protected information, or cause a partial service outage. The flaw is identified in the BI Publisher Integration component of Oracle E‑Business Suite. Based on the description, the attacker does not need to elevate privileges beyond what is already available.

Affected Systems

Affected systems include Oracle Corporation’s Oracle Concurrent Processing product for Enterprise Business Suite, specifically versions 12.2.3 through 12.2.15. The vulnerability is present in the BI Publisher Integration component of this product and is not limited to a single module.

Risk and Exploitability

The CVSS v3.1 base score of 6.3 indicates moderate impact to confidentiality, integrity and availability. The EPSS score of less than 1% means it is unlikely to be exploited in the near future, and it is not listed in CISA’s KEV catalog. However, the attack vector is network-based (HTTP) and requires only low privileges, implying that an external attacker could abuse the flaw to gain partial access to confidential data or disrupt services unless the patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 02:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Oracle security patch CPUJul2026 that addresses the flaw in Oracle Concurrent Processing 12.2.3–12.2.15.
  • After applying the patch, restart the Oracle Concurrent Processing service(s) to load the updated code.
  • Restrict HTTP access to the Oracle Concurrent Processing endpoints to trusted internal networks only to reduce exposure.

Generated by OpenCVE AI on August 4, 2026 at 02:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Denial of Service in Oracle Concurrent Processing

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Denial of Service in Oracle Concurrent Processing

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via HTTP in Oracle Concurrent Processing

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via HTTP in Oracle Concurrent Processing
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Concurrent Processing accessible data as well as unauthorized read access to a subset of Oracle Concurrent Processing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Concurrent Processing. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle concurrent Processing
CPEs cpe:2.3:a:oracle:concurrent_processing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle concurrent Processing
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Concurrent Processing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:36:59.873Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61051

cve-icon Vulnrichment

Updated: 2026-07-24T14:36:41.749Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses