Description
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-07-21
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle Installed Base allows a low‑privileged user who can reach the product over HTTP to create, delete, or modify critical data and obtain full read access to all data exposed by the system. The result is a loss of confidentiality, breach of integrity, and a partial denial of service. The weakness stems from inadequate authentication checks and exposure of sensitive information (CWE‑200, CWE‑269, CWE‑284). The description states that the attacker must be low‑privileged, and it is inferred that unauthenticated access is not required, as the statement does not mention it explicitly.

Affected Systems

Oracle Corporation’s E‑Business Suite, specifically the Create Item Instance component of Oracle Installed Base, is affected on versions 12.2.3 through 12.2.15. Any installation of these versions that exposes the HTTP interface to low‑privileged accounts is vulnerable.

Risk and Exploitability

The CVSS‑3.1 base score of 8.3 highlights high confidentiality and integrity impact with moderate availability impact. The EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the attack requires only network access and a low‑privileged account, making environments that expose the HTTP endpoint a significant risk. No additional user interaction or pre‑existing software condition is required for exploitation.

Generated by OpenCVE AI on August 4, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU patch that addresses this vulnerability for all instances of E‑Business Suite version 12.2.3 through 12.2.15.
  • Configure network settings to restrict HTTP access to Oracle Installed Base to trusted internal hosts and enforce strict role‑based permissions for access.
  • Enable comprehensive logging and regularly review audit logs for unauthorized data modifications or access attempts, and consider isolating the Installed Base with additional network segmentation.

Generated by OpenCVE AI on August 4, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Allows Data Modification in Oracle Installed Base

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Allows Data Modification in Oracle Installed Base

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Oracle Installed Base Remote Authorization Bypass

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Oracle Installed Base Remote Authorization Bypass

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle installed Base
CPEs cpe:2.3:a:oracle:installed_base:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle installed Base
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle Installed Base
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T16:18:24.417Z

Reserved: 2026-07-14T14:54:48.733Z

Link: CVE-2026-62473

cve-icon Vulnrichment

Updated: 2026-07-22T16:18:20.449Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control