Description
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in takeover of Oracle Lease and Finance Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Internal Operations component of Oracle Lease and Finance Management, an Oracle E‑Business Suite application. A low‑privileged attacker who can reach the application over HTTP can leverage a difficult‑to‑exploit flaw that grants them unauthorized privilege escalation, allowing complete takeover of the application. This results in full compromise of confidentiality, integrity, and availability, and corresponds to CWE‑284, an authorization weakness.

Affected Systems

Oracle Lease and Finance Management, part of Oracle E‑Business Suite, is affected. The advisory lists the vulnerable releases as versions 12.2.11 through 12.2.15. No other vendors or product lines are mentioned in the CNA data.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 highlights high severity, while the EPSS score of less than 1 % indicates that current exploit prevalence is very low. It is not included in the CISA KEV catalog. The authoritative vector implies that an attacker only needs network connectivity to the application’s HTTP interface and a low level of privilege; no local access is required.

Generated by OpenCVE AI on August 4, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Lease and Finance Management security patch for versions 12.2.11 through 12.2.15.
  • Restrict HTTP access to the Oracle Lease and Finance Management endpoints to trusted IP ranges and disable unnecessary services.
  • Enforce strict authentication and privilege separation for all user accounts interacting with the application.

Generated by OpenCVE AI on August 4, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Enables Remote Privilege Escalation in Oracle Lease and Finance Management

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Enables Remote Privilege Escalation in Oracle Lease and Finance Management

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation to Full Control via HTTP in Oracle Lease and Finance Management

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation to Full Control via HTTP in Oracle Lease and Finance Management

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in takeover of Oracle Lease and Finance Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle lease And Finance Management
CPEs cpe:2.3:a:oracle:lease_and_finance_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle lease And Finance Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Lease And Finance Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:34:30.540Z

Reserved: 2026-07-08T15:52:20.748Z

Link: CVE-2026-61337

cve-icon Vulnrichment

Updated: 2026-07-22T17:34:26.531Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses