Description
Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Planning Command Center. While the vulnerability is in Oracle Advanced Planning Command Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Planning Command Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Planning Command Center accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Advanced Planning Command Center allows an attacker who already has high‑privilege access and can reach the application via HTTP to compromise the component, enabling unauthorized reading of all accessible data and the ability to insert, update or delete critical information. The vulnerability carries confidentiality and integrity impacts and is identified with a CVSS 7.6 score, indicating high severity. The effect is amplified by a potential scope change that could impact additional Oracle products.

Affected Systems

Oracle Advanced Planning Command Center versions from 12.2.3 through 12.2.15, part of Oracle E‑Business Suite, are affected. No other product or version is listed as impacted.

Risk and Exploitability

The CVSS score of 7.6 indicates a high‑severity flaw, while the EPSS score of less than 1% suggests a low probability of exploitation today. The vulnerability is not in CISA’s KEV catalog. The risk is heightened by the possible scope change. Exploitation requires HTTP network access and an account with high privileges; no additional sophisticated conditions are mentioned.

Generated by OpenCVE AI on August 4, 2026 at 00:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU Jul 2026 patch for Advanced Planning Command Center
  • Limit HTTP access to the component to trusted networks or hosts only
  • Reduce or reallocate high‑privilege accounts that have network visibility of the Advanced Planning Command Center

Generated by OpenCVE AI on August 4, 2026 at 00:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title High Privilege Data Compromise in Oracle Advanced Planning Command Center

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title High Privilege Data Compromise in Oracle Advanced Planning Command Center

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Attack via HTTP Exploits Oracle Advanced Planning Command Center

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Attack via HTTP Exploits Oracle Advanced Planning Command Center

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Planning Command Center. While the vulnerability is in Oracle Advanced Planning Command Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Planning Command Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Planning Command Center accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle advanced Planning Command Center
CPEs cpe:2.3:a:oracle:advanced_planning_command_center:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Planning Command Center
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Advanced Planning Command Center
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:14:38.057Z

Reserved: 2026-07-14T14:54:48.738Z

Link: CVE-2026-62515

cve-icon Vulnrichment

Updated: 2026-07-22T15:26:00.852Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control