Description
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Benefits accessible data as well as unauthorized read access to a subset of Oracle Advanced Benefits accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Benefits. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Advanced Benefits component of Oracle E‑Business Suite suffers an authorization flaw that permits attackers with low‑privilege credentials and network access over HTTP to modify, insert, or delete data, read restricted information, and cause a partial denial of service. This flaw stems from an improper check of user permissions (CWE‑284) and impacts the confidentiality, integrity, and availability of the application.

Affected Systems

The vulnerable product is Oracle Advanced Benefits in Oracle E‑Business Suite. Versions from 12.2.4 up through 12.2.15 are affected.

Risk and Exploitability

The CVSS v3.1 base score of 6.3 signifies a moderate security risk. EPSS is below 1 % suggesting exploitation is unlikely but not impossible, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs low‑privilege membership and network connectivity over HTTP to exploit the flaw, which can lead to unauthorized data manipulation or partial denial of service.

Generated by OpenCVE AI on August 4, 2026 at 01:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch or update to an unaffected release once available.
  • Restrict HTTP access to Oracle Advanced Benefits to trusted administrators or internal networks and block exposure to untrusted external networks.
  • Re‑evaluate and enforce strict role‑based access controls, ensuring that users lacking appropriate permissions cannot perform write operations on benefit data.
  • Monitor application logs for anomalous data modifications or frequent failures indicating possible exploitation.

Generated by OpenCVE AI on August 4, 2026 at 01:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Authorization Flaw in Oracle Advanced Benefits Allows Data Manipulation and Partial DoS

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Authorization Flaw in Oracle Advanced Benefits Allows Data Manipulation and Partial DoS

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Insecure Authorization in Oracle Advanced Benefits Allows Low-Privilege Data Manipulation

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Insecure Authorization in Oracle Advanced Benefits Allows Low-Privilege Data Manipulation

Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Benefits accessible data as well as unauthorized read access to a subset of Oracle Advanced Benefits accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Benefits. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle advanced Benefits
CPEs cpe:2.3:a:oracle:advanced_benefits:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Benefits
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Advanced Benefits
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T14:42:50.858Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61282

cve-icon Vulnrichment

Updated: 2026-07-22T14:42:26.672Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses