Description
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Document Management and Collaboration accessible data as well as unauthorized read access to a subset of Oracle Document Management and Collaboration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Attachments component of Oracle Document Management and Collaboration allows an unauthenticated attacker that can reach the service over HTTP to perform unauthorized updates, inserts, deletes, reads, and to cause a partial denial of service. The flaw is a case of Improper Access Control (CWE‑284) that directly compromises confidentiality, integrity, and availability of the data managed by the application.

Affected Systems

Oracle Document Management and Collaboration, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected, as listed by Oracle for this incident.

Risk and Exploitability

The CVSS score of 7.3 classifies this vulnerability as high severity. The EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers need no authentication and only HTTP network connectivity to target the service, making the attack vector simple but limited to HTTP access. With these privileges the attacker can modify or delete data, read sensitive information, and disrupt service availability, all within the scope of the Document Management and Collaboration domain.

Generated by OpenCVE AI on August 4, 2026 at 01:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch submitted in Oracle’s CPU July 2026 update for Document Management and Collaboration.
  • Limit HTTP access to the Oracle E‑Business Suite service to trusted IP addresses or internal networks through firewall or reverse‑proxy rules.
  • Enable and monitor logging for Attachments module operations and periodically review logs for anomalous activity.

Generated by OpenCVE AI on August 4, 2026 at 01:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP‑Based Data Modification and Partial DoS in Oracle Document Management and Collaboration Attachments

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP‑Based Data Modification and Partial DoS in Oracle Document Management and Collaboration Attachments

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Oracle Document Management Unauthenticated HTTP Access Exploit

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Document Management Unauthenticated HTTP Access Exploit

Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Document Management and Collaboration accessible data as well as unauthorized read access to a subset of Oracle Document Management and Collaboration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle document Management And Collaboration
CPEs cpe:2.3:a:oracle:document_management_and_collaboration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle document Management And Collaboration
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Document Management And Collaboration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:09:29.458Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61271

cve-icon Vulnrichment

Updated: 2026-07-22T15:08:46.047Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses