Description
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Public Sector Financials version 12.2.3 through 12.2.15 contains an access‑control bypass in the Internal Operations component that allows a low‑privileged network attacker to access sensitive financial data. The flaw enables unauthorized data retrieval without proper authentication, potentially exposing confidential records. The weakness is classified as CWE‑284, reflecting a permission‑or‑authorization failure.

Affected Systems

The affected product is Oracle Public Sector Financials from Oracle Corporation, specifically versions 12.2.3 to 12.2.15. These versions run the Internal Operations component that is vulnerable to the described access‑control bypass.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates a moderate severity, with a focus on confidentiality impact. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to send specially crafted HTTP requests to the exposed Internal Operations endpoint, and the attacker only needs low‑level network privileges to exploit the flaw.

Generated by OpenCVE AI on August 4, 2026 at 15:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 security patch that resolves the access‑control bypass in Oracle Public Sector Financials.
  • Restrict inbound HTTP traffic to Oracle Public Sector Financials through firewall rules or network segmentation, limiting access to trusted administrative hosts.
  • Disable the vulnerable Internal Operations component until a patch can be applied, preventing unauthenticated or low‑privileged users from accessing the endpoint.

Generated by OpenCVE AI on August 4, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Access‑Control Bypass in Oracle Public Sector Financials

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Access‑Control Bypass in Oracle Public Sector Financials

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Oracle Public Sector Financials Leading to Unauthorized Data Access

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Oracle Public Sector Financials Leading to Unauthorized Data Access

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Public Sector Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:57:11.623Z

Reserved: 2026-07-14T14:54:48.734Z

Link: CVE-2026-62480

cve-icon Vulnrichment

Updated: 2026-07-22T15:57:07.456Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses