Description
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in takeover of Oracle Lease and Finance Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Lease and Finance Management, part of Oracle E‑Business Suite, has a vulnerability in the Internal Operations component that permits a high‑privileged attacker who can reach the system over HTTP to exploit the flaw, resulting in total takeover of the application and loss of confidentiality, integrity, and availability for affected data and processes.

Affected Systems

Oracle Lease and Finance Management versions 12.2.14 through 12.2.15 are affected. These instances provide finance functionality within Oracle E‑Business Suite.

Risk and Exploitability

The CVSS v3.1 score of 7.2 indicates a high impact with low complexity. The EPSS score of less than 1% suggests that exploitation attempts are rare or currently unobserved, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based via HTTP and requires a high‑privileged attacker with access rights. Successful exploitation would result in complete takeover of the application, causing unacceptable damage to the organization’s financial data and processes.

Generated by OpenCVE AI on August 4, 2026 at 00:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses the vulnerability for versions 12.2.14 and 12.2.15
  • Restrict HTTP access to the Oracle Lease and Finance Management instance to trusted networks or IP ranges only
  • Implement network segmentation and enforce strict firewall rules for the application

Generated by OpenCVE AI on August 4, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title High‑Privilege HTTP Exploit Allows Takeover of Oracle Lease and Finance Management

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title High‑Privilege HTTP Exploit Allows Takeover of Oracle Lease and Finance Management

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Full Application Takeover in Oracle Lease and Finance Management via HTTP

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Full Application Takeover in Oracle Lease and Finance Management via HTTP

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in takeover of Oracle Lease and Finance Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle lease And Finance Management
CPEs cpe:2.3:a:oracle:lease_and_finance_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle lease And Finance Management
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Lease And Finance Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:45:33.624Z

Reserved: 2026-07-08T15:52:20.748Z

Link: CVE-2026-61336

cve-icon Vulnrichment

Updated: 2026-07-22T17:45:14.877Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management