Description
Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle U.S. Federal Financials accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an information disclosure flaw (CWE-200) in Oracle U.S. Federal Financials. An attacker with low system privilege who can reach the application via HTTP can obtain unauthorized read access to a subset of data that the application exposes. It affects confidentiality only; integrity and availability are unaffected, and the CVSS 3.1 Base Score of 4.3 reflects the moderate risk level.

Affected Systems

The flaw exists in the Oracle U.S. Federal Financials component of Oracle E‑Business Suite, specifically the Internal Operations module. Affected supported versions range from 12.2.3 through 12.2.15. The vulnerability is reachable over the network through HTTP requests to the application.

Risk and Exploitability

At the time of analysis the CVSS score is 4.3, indicating a moderate severity. The EPSS score is below 1 %, suggesting that active exploitation is uncommon. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw from the network without elevated privileges, using a simple HTTP request to trigger the data disclosure. The risk is therefore moderate but with a low chance of exploitation in the wild.

Generated by OpenCVE AI on August 4, 2026 at 01:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle vendor patch that addresses the unauthorized read access in Oracle U.S. Federal Financials for all affected versions (12.2.3–12.2.15).
  • Configure the Oracle U.S. Federal Financials effectively blocking unauthenticated or low‑privileged external access.
  • Review and enforce role‑based access controls within the application to ensure that users have read rights only for data they are permitted to view; in particular limit the subset of data that can be exposed through the affected module.

Generated by OpenCVE AI on August 4, 2026 at 01:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Disclosure in Oracle U.S. Federal Financials via HTTP

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Disclosure in Oracle U.S. Federal Financials via HTTP

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via Low-Privilege HTTP Exploit in Oracle U.S. Federal Financials

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via Low-Privilege HTTP Exploit in Oracle U.S. Federal Financials

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle U.S. Federal Financials. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle U.S. Federal Financials accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle u.s. Federal Financials
CPEs cpe:2.3:a:oracle:u.s._federal_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle u.s. Federal Financials
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle U.s. Federal Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:33:22.611Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61292

cve-icon Vulnrichment

Updated: 2026-07-22T18:33:19.681Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor