Description
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Hub accessible data as well as unauthorized read access to a subset of Oracle Product Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Item Catalog component of Oracle Product Hub within Oracle E‑Business Suite that enables a low‑privileged attacker with network access through HTTP to delete, insert, or update accessible data, read a subset of the data, or perform a partial denial of service. This improper access control flaw (CWE‑284) allows unauthorized manipulation of data and exposure of sensitive information, compromising the confidentiality, integrity, and availability of the affected system.

Affected Systems

Oracle Corporation’s Oracle Product Hub for Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. Users of the Item Catalog feature within this product range are exposed to the described risks.

Risk and Exploitability

The CVSS 3.1 base score of 6.3 indicates moderate severity, amplified by the low attack complexity and low privileges required; no user interaction is needed. The EPSS score of less than 1% suggests a low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential for data alteration and service disruption warrants immediate attention.

Generated by OpenCVE AI on August 4, 2026 at 01:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enforce strict role‑based access controls for the Item Catalog to limit read, write, and delete permissions to authorized users, mitigating CWE‑284.
  • Restrict HTTP access to Oracle Product Hub by limiting exposure to trusted internal networks or firewall rules.
  • Implement monitoring and alerting to detect unauthorized data modifications or repeated access attempts to the Item Catalog.

Generated by OpenCVE AI on August 4, 2026 at 01:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Enables Data Modification and Partial Denial in Oracle Product Hub

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Enables Data Modification and Partial Denial in Oracle Product Hub

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Leading to Unauthorized Data Modification and Partial Denial of Service in Oracle Product Hub

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Leading to Unauthorized Data Modification and Partial Denial of Service in Oracle Product Hub

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Hub accessible data as well as unauthorized read access to a subset of Oracle Product Hub accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Hub. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle product Hub
CPEs cpe:2.3:a:oracle:product_hub:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Hub
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Product Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T14:58:33.285Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61274

cve-icon Vulnrichment

Updated: 2026-07-22T14:58:22.652Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses