Description
Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Outlook Sync Win 32). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales for Handhelds. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Sales for Handhelds accessible data as well as unauthorized read access to a subset of Oracle Sales for Handhelds accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Sales for Handhelds. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Sales for Handhelds permits a low‑privileged user with network access to modify or delete data, read restricted information, and trigger a partial service outage. The vulnerability is grounded in improper enforcement of access controls (CWE‑284), leading to confidentiality, integrity, and availability impacts. Successful exploitation results in unauthorized database changes, exposure of internal data, and disruption of business operations.

Affected Systems

Oracle Corporation’s Oracle Sales for Handhelds, versions 12.2.3 through 12.2.15 of the Oracle E‑Business Suite. These affected releases are listed under the component Outlook Sync Win 32 and are part of the broader Sales for Handhelds product line.

Risk and Exploitability

The CVSS 3.1 base score of 6.3 indicates moderate severity, yet the low exploitation difficulty and low privilege requirement raise its practical threat. The EPSS score of less than 1% signals currently low probability of exploitation in the wild, and the vulnerability is not yet catalogued in CISA’s KEV list. Nonetheless, network‑based attackers can exploit the bug through HTTP traffic to gain unauthorized access and disrupt service.

Generated by OpenCVE AI on August 4, 2026 at 01:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle E-Business Suite patch that fixes the access control flaw for Sales for Handhelds.
  • Restrict access to the Sales for Handhelds HTTP endpoint to trusted IP ranges or enforce VPN protection.
  • Ensure role-based permissions are limited to the minimum required for each user and validate that no elevated rights are granted without justification.
  • Enable comprehensive audit trails for data modification and monitor logs for anomalous activity.

Generated by OpenCVE AI on August 4, 2026 at 01:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Manipulation via HTTP in Oracle Sales for Handhelds

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Manipulation via HTTP in Oracle Sales for Handhelds

Mon, 27 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via HTTP in Oracle Sales for Handhelds

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via HTTP in Oracle Sales for Handhelds

Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Outlook Sync Win 32). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales for Handhelds. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Sales for Handhelds accessible data as well as unauthorized read access to a subset of Oracle Sales for Handhelds accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Sales for Handhelds. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle sales For Handhelds
CPEs cpe:2.3:a:oracle:sales_for_handhelds:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle sales For Handhelds
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Sales For Handhelds
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T14:44:14.845Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61280

cve-icon Vulnrichment

Updated: 2026-07-22T14:43:42.526Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses