Description
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Benefits accessible data as well as unauthorized read access to a subset of Oracle Advanced Benefits accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Benefits. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw (CWE-284) in Oracle Advanced Benefits’ Self Service Benefits component. It allows a low‑privileged user who can reach the application via HTTP to update, insert, or delete benefit records, read sensitive benefit information that should not be exposed, or cause a partial denial of service. These actions can compromise the confidentiality, integrity, and availability of the data managed by the application.

Affected Systems

Oracle Advanced Benefits, part of Oracle E‑Business Suite, is affected in the Self Service Benefits module. Versions 12.2.3 through 12.2.15 contain the weakness. Organizations using any of these releases should verify and isolate the component.

Risk and Exploitability

The CVSS 3.1 Base Score of 6.3 indicates a moderate severity. The EPSS score of less than 1 % indicates very low current exploitation activity, and the vulnerability is not listed in CISA’s KEV catalog. However, the flaw can be exploited from any host that can reach the service over HTTP with a low‑privileged account, making the attack path simple. The potential to modify or delete benefit records or read protected data means that a successful exploit could lead to significant data loss or corruption, and the possible denial of service could disrupt business operations.

Generated by OpenCVE AI on August 4, 2026 at 15:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Oracle Advanced Benefits as soon as it is released.
  • Limit HTTP access to the Advanced Benefits service to trusted subnets or VPNs using firewalls or segmentation.
  • Enforce the principle of least privilege by restricting user roles in the Self Service Benefits module to only the permissions required.
  • Monitor API and database activity for anomalous changes to benefit records.

Generated by OpenCVE AI on August 4, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Advanced Benefits Enabling Unauthorized Data Modification

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Advanced Benefits Enabling Unauthorized Data Modification

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Partial Denial of Service in Oracle Advanced Benefits via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Partial Denial of Service in Oracle Advanced Benefits via HTTP

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self Service Benefits). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Benefits accessible data as well as unauthorized read access to a subset of Oracle Advanced Benefits accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Benefits. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle advanced Benefits
CPEs cpe:2.3:a:oracle:advanced_benefits:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Benefits
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Advanced Benefits
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T14:02:28.564Z

Reserved: 2026-07-14T14:54:48.740Z

Link: CVE-2026-62542

cve-icon Vulnrichment

Updated: 2026-07-22T14:02:23.196Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses