Description
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unknown software defect in Oracle Complex Maintenance, Repair and Overhaul enables a low privileged network attacker to read all data exposed by the application and to cause a partial denial of service. The problem afflicts only the Production component of the product, but because the vulnerability changes the security scope, successful exploitation can affect other Oracle E‑Business Suite modules. The flaw does not require user interaction, can be triggered over HTTP, and requires only high authentication complexity and a low privilege level to execute.

Affected Systems

The affected product is Oracle Complex Maintenance, Repair and Overhaul, a component of Oracle E‑Business Suite, with supported versions ranging from 12.2.3 to 12.2.15. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 indicates moderate to high severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but because the attack vector is network‑based with no user interaction and involves a scope change the likelihood of exploitation for attackers who can reach the target via HTTP is significant. The vulnerability allows unauthorized information disclosure and a partial availability impact, giving an attacker the ability to exfiltrate confidential data or disrupt services.

Generated by OpenCVE AI on August 21, 2026 at 11:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s security update for the August 2026 release as specified in the Oracle Security Alert
  • Restrict HTTP access to the Complex Maintenance, Repair and Overhaul component to trusted network segments or IP ranges
  • Implement continuous monitoring of application logs for unusual read or denial‑of‑service patterns to detect attempted exploitation

Generated by OpenCVE AI on August 21, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle complex Maintenance Repair And Overhaul
CPEs cpe:2.3:a:oracle:complex_maintenance_repair_and_overhaul:*:*:*:*:*:*:*:*
Vendors & Products Oracle complex Maintenance Repair And Overhaul

Fri, 21 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title Oracle Complex Maintenance, Repair and Overhaul Unauthenticated Data Exposure and Denial of Service

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L).
First Time appeared Oracle
Oracle complex Maintenance Repair And Overhaul
CPEs cpe:2.3:a:oracle:complex_maintenance__repair_and_overhaul:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle complex Maintenance Repair And Overhaul
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Oracle Complex Maintenance Repair And Overhaul Complex Maintenance Repair And Overhaul
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:16.190Z

Reserved: 2026-07-08T15:52:20.746Z

Link: CVE-2026-61306

cve-icon Vulnrichment

Updated: 2026-08-19T12:12:40.634Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:59.250

Modified: 2026-08-31T18:09:17.713

Link: CVE-2026-61306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:45:04Z

Weaknesses