Description
Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Price Protection accessible data as well as unauthorized read access to a subset of Oracle Price Protection accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Price Protection. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Price Protection permits a low‑privileged network attacker to perform unauthorized insert, update, or delete operations on protected data and to read restricted data. Additionally, the attacker can trigger a partial denial of service. These capabilities expose weaknesses in access control and information confidentiality, aligned with CWE‑200, CWE‑269, and CWE‑284, and result in confidentiality, integrity, and availability impacts as reflected in the CVSS vector.

Affected Systems

Oracle Corporation’s Oracle Price Protection component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected. These releases fall under the Oracle E‑Business Suite product family.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 Base Score of 6.3, indicating moderate severity. The EPSS score of less than 1% implies a low but nonzero exploitation likelihood. It is not listed in the CISA KEV catalog. The likely attack vector is an HTTP request that a user with low privileges can send to an exposed endpoint in the Price Protection service, leveraging insufficient access controls to gain unauthorized data modification, read, or partial service disruption.

Generated by OpenCVE AI on August 4, 2026 at 16:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security updates portal for any patch or advisory specific to Price Protection versions 12.2.3 through 12.2.15.
  • Restrict external network exposure of the Price Protection service to internal or trusted networks, limiting access to authorized hosts only.
  • Enforce strict role‑based access control, ensuring that only users with the minimum required privileges can interact with the Price Protection data.

Generated by OpenCVE AI on August 4, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial DoS via Low‑Privileged HTTP Access in Oracle Price Protection

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial DoS via Low‑Privileged HTTP Access in Oracle Price Protection

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial DoS via Low-Privilege HTTP Access in Oracle Price Protection

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial DoS via Low-Privilege HTTP Access in Oracle Price Protection

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Price Protection accessible data as well as unauthorized read access to a subset of Oracle Price Protection accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Price Protection. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle price Protection
CPEs cpe:2.3:a:oracle:price_protection:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle price Protection
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Price Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:06:34.229Z

Reserved: 2026-07-08T15:52:20.746Z

Link: CVE-2026-61304

cve-icon Vulnrichment

Updated: 2026-07-22T18:06:25.222Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control