Description
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Lease and Finance Management accessible data as well as unauthorized read access to a subset of Oracle Lease and Finance Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Lease and Finance Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Lease Authoring component of Oracle Lease and Finance Management allows an attacker with low privileges and HTTP network access to bypass authorization checks and perform unauthorized updates, inserts, deletions, and read operations on protected data, as well as trigger a partial denial of service. The weakness is rooted in improper access control and missing authorization checks, corresponding to CWE-269, CWE-284, and CWE-306. The impact spans confidentiality, integrity, and availability of the application data, though each tier of impact is classified as low.

Affected Systems

Oracle Lease and Finance Management, part of Oracle E‑Business Suite, is affected for releases 12.2.3 through 12.2.15. The Lease Authoring component must be evaluated for exposure to external HTTP traffic, as the vulnerability can be exploited by any user that can connect to the application over the network.

Risk and Exploitability

The CVSS 3.1 base score of 6.3 indicates moderate severity, and the EPSS score falling below 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, because only low privileges and direct HTTP access are required, organizations that expose Lease and Finance Management to the network face a significant risk of unauthorized data manipulation and partial service disruption and should remediate promptly.

Generated by OpenCVE AI on August 4, 2026 at 00:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle July 2026 CPU update patch for Lease and Finance Management
  • Restrict HTTP access to the Lease and Finance Management application to trusted internal networks or IP ranges using firewall or VPN controls
  • Review and tighten role‑based access controls in the Lease Authoring component to eliminate low‑privileged permissions that enable data modification
  • After remediation, conduct focused penetration testing against Lease Authoring to confirm that authorization checks are effective

Generated by OpenCVE AI on August 4, 2026 at 00:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low Privilege Authorization Bypass in Oracle Lease and Finance Management Enable Data Modification and Partial Denial of Service

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Authorization Bypass in Oracle Lease and Finance Management Enable Data Modification and Partial Denial of Service

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Access to Data and Partial Denial of Service in Oracle Lease and Finance Management

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Access to Data and Partial Denial of Service in Oracle Lease and Finance Management

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Lease and Finance Management accessible data as well as unauthorized read access to a subset of Oracle Lease and Finance Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Lease and Finance Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle lease And Finance Management
CPEs cpe:2.3:a:oracle:lease_and_finance_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle lease And Finance Management
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Lease And Finance Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T16:29:54.379Z

Reserved: 2026-07-14T14:54:48.734Z

Link: CVE-2026-62474

cve-icon Vulnrichment

Updated: 2026-07-22T16:29:50.598Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function