Description
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Learning Management accessible data as well as unauthorized read access to a subset of Oracle Learning Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Learning Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Import And Export component of Oracle Learning Management, allowing a user with low privileges and network access via HTTP to gain unauthorized capabilities. The flaw enables attackers to update, insert, or delete data, read restricted data, and trigger a partial denial of service, impacting confidentiality, integrity, and availability. The weakness is a combination of improper access control (CWE‑284), information exposure (CWE‑200), and SQL injection (CWE‑89).

Affected Systems

Oracle Learning Management versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS score is 6.3, indicating a moderate severity. The EPSS score is less than 1 percent, suggesting a low probability of exploitation, and it is not listed in the CISA KEV catalog. Nonetheless, exploitation would enable a low‑privileged attacker to modify or read data and cause service disruption. The likely attack vector is remote access over HTTP from a non‑privileged user, making it easily exploitable by anyone who can reach the service on the network.

Generated by OpenCVE AI on August 4, 2026 at 00:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Learning Management, released in Oracle CPU July 2026, to remove the vulnerability.
  • Restrict network access to the Learning Management HTTP interface by allowing only trusted IP addresses or VPN connections.
  • Enforce stricter role‑based access control to limit permissions for updating, inserting, or deleting Learning Management data.
  • If a patch cannot be applied immediately, temporarily disable the Import And Export functionality in the web configuration to prevent the exploit.

Generated by OpenCVE AI on August 4, 2026 at 00:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial DOS via Import/Export in Oracle Learning Management

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial DOS via Import/Export in Oracle Learning Management

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification and Partial Denial of Service in Oracle Learning Management

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification and Partial Denial of Service in Oracle Learning Management

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-89
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Learning Management accessible data as well as unauthorized read access to a subset of Oracle Learning Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Learning Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle learning Management
CPEs cpe:2.3:a:oracle:learning_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle learning Management
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Learning Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:46:56.854Z

Reserved: 2026-07-14T14:54:48.739Z

Link: CVE-2026-62527

cve-icon Vulnrichment

Updated: 2026-07-22T13:46:49.073Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')