Description
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Common Applications Calendar accessible data as well as unauthorized read access to a subset of Oracle Common Applications Calendar accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Applications Calendar. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Calendar Synchronizations component of Oracle Common Applications Calendar allows a low‑privileged attacker with network access via HTTP to perform unauthorized insert, update or delete operations on calendar data, read restricted records, and trigger a partial denial of service. This is reflected in the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L) and maps to CWE‑200, CWE‑284 and CWE‑89 weaknesses. The vulnerability permits tampering with data integrity, disclosure of confidential calendar information and disruption of service for authorized users.

Affected Systems

Oracle Common Applications Calendar, versions 12.2.3 through 12.2.15, is affected.

Risk and Exploitability

The CVSS v3.1 base score of 6.3 indicates moderate severity. Exploitation requires only network connectivity to the vulnerable HTTP endpoint and does not need user interaction, but the EPSS score of less than 1 % shows a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would target the Calendar Synchronizations endpoint to gain unauthorized data modification or partial service disruption as described by the vendor advisory.

Generated by OpenCVE AI on August 4, 2026 at 16:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s security patch for Calendar Synchronizations as described in the July 2026 CPU.
  • Restrict HTTP access to the Calendar application to authorized users only, using network segmentation and role‑based access controls, and monitor logs for suspicious activity.
  • Implement logging and rate‑limiting on the Calendar Synchronizations endpoint to detect and mitigate potential partial denial‑of‑service attacks.

Generated by OpenCVE AI on August 4, 2026 at 16:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Calendar Synchronizations in Oracle Common Applications Calendar

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Calendar Synchronizations in Oracle Common Applications Calendar

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Oracle Common Applications Calendar Calendar Synchronizations Unauthorized Data Modification & Partial Denial of Service

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Oracle Common Applications Calendar Calendar Synchronizations Unauthorized Data Modification & Partial Denial of Service

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-89
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Common Applications Calendar accessible data as well as unauthorized read access to a subset of Oracle Common Applications Calendar accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Applications Calendar. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle common Applications Calendar
CPEs cpe:2.3:a:oracle:common_applications_calendar:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle common Applications Calendar
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Common Applications Calendar
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:05:31.859Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61294

cve-icon Vulnrichment

Updated: 2026-07-22T18:05:16.162Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')