Description
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data as well as unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper access control in the Internal Operations component of Oracle Public Sector Financials. A user with only low privileges can exploit standard HTTP endpoints to add, delete, or alter data and to read a subset of entries that should be protected. This violation of confidentiality and integrity affects only a portion of the system’s data, as defined by the product’s access policies.

Affected Systems

Oracle Public Sector Financials versions 12.2.3 through 12.2.15, part of Oracle E‑Business Suite, are susceptible to this permission‑granting issue.

Risk and Exploitability

The vulnerability can be triggered over ordinary HTTP traffic by an attacker who has network access and low‑privilege credentials. The CVSS 3.1 base score of 5.4 indicates moderate risk, while an EPSS less than 1 % suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, but any compromised account can modify or read restricted data, potentially impacting the integrity and confidentiality of financial records.

Generated by OpenCVE AI on August 4, 2026 at 00:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Public Sector Financials patch delivered in the CPU July 2026 update to correct the improper access control.
  • Configure the Internal Operations HTTP endpoints to accept traffic only from approved IP ranges and enforce least‑privilege roles for database users.
  • Implement network firewall or proxy rules to block unauthenticated or untrusted IP addresses from accessing the affected services.

Generated by OpenCVE AI on August 4, 2026 at 00:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Permitting Data Modification and Read by Low-privilege Users in Oracle Public Sector Financials

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Permitting Data Modification and Read by Low-privilege Users in Oracle Public Sector Financials

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authorization Escalation in Oracle Public Sector Financials via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authorization Escalation in Oracle Public Sector Financials via HTTP

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Financials accessible data as well as unauthorized read access to a subset of Oracle Public Sector Financials accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Public Sector Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:59:06.747Z

Reserved: 2026-07-14T14:54:48.735Z

Link: CVE-2026-62482

cve-icon Vulnrichment

Updated: 2026-07-22T15:59:02.537Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses