Description
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data as well as unauthorized read access to a subset of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Labor Distribution, part of Oracle E‑Business Suite, contains an access control weakness that is easily exploitable by a low‑privileged attacker who can reach the system over HTTP. The flaw allows the attacker to update, insert, delete, and read data that should be restricted, leading to confidentiality and integrity violations without affecting availability. The vulnerability is attributed to improper authorization checks (CWE‑284).

Affected Systems

Oracle Corporation’s Oracle Labor Distribution product, versions 12.2.3 through 12.2.15, is impacted. These versions are part of the internal operations component of the E‑Business Suite.

Risk and Exploitability

The CVSS 3.1 score of 5.4 indicates a moderate risk to confidentiality and integrity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely attack paths involve an HTTP endpoint that can be accessed by low‑privileged users; the attacker does not require administrative privileges or network isolation to succeed, but must have network connectivity to the target host.

Generated by OpenCVE AI on August 4, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that addresses CVE‑2026‑61200
  • Restrict HTTP access to the Oracle Labor Distribution interface to trusted IP ranges or VPNs
  • Audit and review database permissions and user roles to ensure least‑privilege access

Generated by OpenCVE AI on August 4, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Improper Access Control in Oracle Labor Distribution

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Improper Access Control in Oracle Labor Distribution

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Disclosure via HTTP in Oracle Labor Distribution

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Disclosure via HTTP in Oracle Labor Distribution

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Labor Distribution accessible data as well as unauthorized read access to a subset of Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle labor Distribution
CPEs cpe:2.3:a:oracle:labor_distribution:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle labor Distribution
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Labor Distribution
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:26:47.912Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61200

cve-icon Vulnrichment

Updated: 2026-07-22T18:26:43.557Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses