Description
Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.215. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Teleservice accessible data as well as unauthorized read access to a subset of Oracle Teleservice accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Service Diagnostics Scripts component of Oracle Teleservice lets an unauthenticated attacker who can reach the service over HTTP update, insert, or delete accessible data, as well as read a subset of data. The weakness is improper access control (CWE‑284), resulting in unauthorized tampering with data integrity and potential leakage of confidential information.

Affected Systems

Oracle Teleservice within Oracle E‑Business Suite is impacted. Versions 12.2.3 to 12.215 are vulnerable per Oracle’s CPU July 2026 alert. Any deployment of these Teleservice versions that exposes the HTTP interface is at risk.

Risk and Exploitability

The CVSS v3.1 base score of 6.5 indicates moderate severity with low confidentiality and integrity impact. The EPSS score is below 1%, reflecting a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated HTTP request to the Teleservice endpoint; no credentials are required, but the attacker must have network access to the service.

Generated by OpenCVE AI on August 4, 2026 at 01:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 security patch for Oracle Teleservice to remove the unauthorized access flaw.
  • Restrict HTTP access to the Teleservice interfaces through firewall rules or network segmentation, allowing only trusted hosts to reach the service.
  • Enforce authentication and role‑based access controls on all Teleservice operations to prevent unauthorized data modifications and reads.

Generated by OpenCVE AI on August 4, 2026 at 01:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification and Disclosure in Oracle Teleservice

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification in Oracle Teleservice

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification in Oracle Teleservice

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.215. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Teleservice. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Teleservice accessible data as well as unauthorized read access to a subset of Oracle Teleservice accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle teleservice
CPEs cpe:2.3:a:oracle:teleservice:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle teleservice
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Teleservice
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:15:49.608Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61262

cve-icon Vulnrichment

Updated: 2026-07-22T18:15:44.738Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses