Description
Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized read access to a subset of Oracle Price Protection accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability occurs in the Oracle Price Protection component of Oracle E‑Business Suite when accessed via HTTP. The flaw allows an attacker with low privileges and network access to create, delete, or alter data records. It also permits the reader to view subsets of the data, thereby impacting confidentiality and integrity. The CVSS vector indicates a network-based attack (AV:N) that requires low authorization (PR:L) and has no requirement for user interaction (UI:N).

Affected Systems

Oracle Corporation’s Oracle Price Protection product is affected, specifically versions 12.2.3 through 12.2.15. These installations rely on secure price data management.

Risk and Exploitability

The CVSS base score of 7.1 classifies the vulnerability as high severity, though the EPSS score of less than 1% suggests exploitation is unlikely at the current moment. The vulnerability is not listed in the CISA KEV catalog and thus has no known active exploits. However, because the attack surface is a publicly exposed HTTP interface, a determined adversary could leverage this flaw to compromise data integrity and confidentiality, especially if other access controls are weak.

Generated by OpenCVE AI on August 4, 2026 at 00:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Price Protection patch that addresses CVE-2026-61334.
  • Restrict HTTP access to the Oracle Price Protection service to trusted IP ranges using firewall or network segmentation.
  • Continuously monitor system logs for unexpected write or read operations on Price Protection data.

Generated by OpenCVE AI on August 4, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title HTTP Access Allows Low-Privilege Data Modification in Oracle Price Protection

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title HTTP Access Allows Low-Privilege Data Modification in Oracle Price Protection

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Access Enables Data Manipulation in Oracle Price Protection

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Access Enables Data Manipulation in Oracle Price Protection

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Price Protection accessible data as well as unauthorized read access to a subset of Oracle Price Protection accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
First Time appeared Oracle
Oracle price Protection
CPEs cpe:2.3:a:oracle:price_protection:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle price Protection
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Oracle Price Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:49:05.547Z

Reserved: 2026-07-08T15:52:20.748Z

Link: CVE-2026-61334

cve-icon Vulnrichment

Updated: 2026-07-22T17:47:48.201Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses