Description
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Purchasing allows a low-privileged attacker with network access through HTTP to achieve a complete compromise of the application, affecting confidentiality, integrity, and availability. The flaw is difficult to exploit but succeeds in taking over the system when triggered, resulting in full control over Oracle Purchasing. The weakness is characterized by CWE-269, CWE-284, CWE-287, and CWE-306.

Affected Systems

Oracle Purchasing in Oracle E‑Business Suite, with affected releases 12.2.11 through 12.2.15.

Risk and Exploitability

The CVSS v3.1 base score is 7.5, indicating a high severity level. The EPSS score of <1% shows a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to be a low‑privileged user with network access to the HTTP endpoint; once leveraged, the attacker can take full control of the application.

Generated by OpenCVE AI on August 4, 2026 at 00:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Purchasing to a non‑vulnerable version (12.2.16 or later) or apply the vendor’s patch from the latest Oracle CPU update
  • Restrict HTTP access to Oracle Purchasing by limiting it to trusted IP ranges or internal networks using firewall rules
  • Enforce least privilege on user accounts accessing Oracle Purchasing to minimize the potential impact of a successful attack

Generated by OpenCVE AI on August 4, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP-Based Compromise of Oracle Purchasing Allowing Full Takeover

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP-Based Compromise of Oracle Purchasing Allowing Full Takeover

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Privilege escalation leading to full takeover of Oracle Purchasing

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege escalation leading to full takeover of Oracle Purchasing

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle purchasing
CPEs cpe:2.3:a:oracle:purchasing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle purchasing
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Purchasing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:52:31.891Z

Reserved: 2026-07-14T14:54:48.736Z

Link: CVE-2026-62493

cve-icon Vulnrichment

Updated: 2026-07-22T15:52:27.412Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function