Description
Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Secure Enterprise Search. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Suite Secure Enterprise Search accessible data as well as unauthorized read access to a subset of Oracle E-Business Suite Secure Enterprise Search accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Search Integration Engine component of Oracle E-Business Suite Secure Enterprise Search allows an attacker with low privileges to modify, insert, or delete data and to read restricted data over HTTP. The weakness is an improper access control, classified as CWE‑284, that undermines data integrity and confidentiality without providing remote code execution.

Affected Systems

The issue affects Oracle E-Business Suite Secure Enterprise Search versions 12.2.3 through 12.2.15 from Oracle Corporation. Users operating these releases with the Search Integration Engine exposed to the network are susceptible to exploitation.

Risk and Exploitability

The CVSS v3.1 base score of 5.4 reflects a moderate severity while the EPSS score of less than 1% indicates that active exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits. Attackers must possess a low‑privilege user account and be able to reach the service over HTTP; no special permissions beyond this are required. Successful exploitation can lead to unauthorized data manipulation and partial data disclosure, potentially disrupting business processes and corrupting business data.

Generated by OpenCVE AI on August 4, 2026 at 01:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or update for Secure Enterprise Search to a version later than 12.2.15
  • Limit HTTP access to the Search Integration Engine to trusted hosts or networks using firewall or ACL rules
  • Enforce strict access controls so that only authorized users can perform data modification or read operations

Generated by OpenCVE AI on August 4, 2026 at 01:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Read via Low-Privileged HTTP Access in Oracle E-Business Suite Secure Enterprise Search

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Read via Improper Access Control in Oracle Secure Enterprise Search

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Read via Improper Access Control in Oracle Secure Enterprise Search

Mon, 27 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Unauthorized Data Modification via HTTP in Oracle E-Business Suite Secure Enterprise Search

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Unauthorized Data Modification via HTTP in Oracle E-Business Suite Secure Enterprise Search
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Secure Enterprise Search. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Suite Secure Enterprise Search accessible data as well as unauthorized read access to a subset of Oracle E-Business Suite Secure Enterprise Search accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle e-business Suite Secure Enterprise Search
CPEs cpe:2.3:a:oracle:e-business_suite_secure_enterprise_search:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle e-business Suite Secure Enterprise Search
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle E-business Suite Secure Enterprise Search
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:19:23.242Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61060

cve-icon Vulnrichment

Updated: 2026-07-24T14:19:18.573Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses