Description
Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Sales accessible data as well as unauthorized update, insert or delete access to some of Oracle Sales accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker with network access via HTTP can exploit a flaw in Oracle Sales, part of Oracle E‑Business Suite, to bypass normal access controls and read or modify critical data. The vulnerability exposes both confidentiality — by allowing the attacker to view sensitive sales information — and integrity — by enabling unauthorized insert, update, or delete operations on the database. The underlying weakness is an access‑control failure (CWE-284).

Affected Systems

Oracle Sales, Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. These versions include the Internal Operations component and are reachable over HTTP. No other Oracle product versions are listed as impacted.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 reflects a medium‑to‑high severity impact with high confidentiality loss and low integrity loss. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network access to the HTTP endpoint; the exploit requires low privileged user credentials on the target network. Successful exploitation grants the attacker full access to all Sales‑accessible data and the ability to modify or delete records.

Generated by OpenCVE AI on August 21, 2026 at 08:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for CVE-2026-62601 applicable to the affected Oracle Sales version.
  • Restrict HTTP access to Oracle Sales to trusted IP ranges or enforce network segmentation to limit exposure.
  • Enable logging and monitor for unauthorized data access attempts, and conduct periodic security reviews of access controls.

Generated by OpenCVE AI on August 21, 2026 at 08:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle e-business Suite
CPEs cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:sales:-:*:*:*:*:*:*:*
Vendors & Products Oracle e-business Suite

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title HTTP Access Control Exploit in Oracle Sales Enables Unauthorized Data Operations
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Sales accessible data as well as unauthorized update, insert or delete access to some of Oracle Sales accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle sales
CPEs cpe:2.3:a:oracle:sales:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle sales
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle E-business Suite Sales
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:17:27.684Z

Reserved: 2026-07-14T14:54:48.744Z

Link: CVE-2026-62601

cve-icon Vulnrichment

Updated: 2026-08-25T14:19:20.968Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:12.440

Modified: 2026-08-31T15:08:31.143

Link: CVE-2026-62601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:45:12Z

Weaknesses