Description
Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Partner Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Partner Management enables an unauthenticated attacker with HTTP network access to retrieve or modify data. The weakness allows the attacker to read confidential data, insert or delete records, and gain full control over data accessible in the application. The impact spans confidentiality and, in certain configurations, integrity, as documented by a CVSS 3.1 score of 8.2, with a scope change effect.

Affected Systems

Oracle Corporation’s Oracle Partner Management component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is impacted. The product is identified as a partner management module and is exposed via web interfaces that accept HTTP traffic.

Risk and Exploitability

The vulnerability is exploitable by users with no authentication and requires an attacker to have network access to the target HTTP endpoint. While successful exploitation needs a second human interaction, the weakness can still lead to significant data compromise. The CVSS score reflects moderate to high severity, and the EPSS score is not available, but the lack of a KEV listing suggests exploitation is not yet widely documented. The scope change indicates that compromise of this module may affect other integrated products and services.

Generated by OpenCVE AI on August 19, 2026 at 11:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Partner Management patch referenced in the Oracle security alert for versions 12.2.3 through 12.2.15
  • Restrict inbound HTTP access to the Partner Management application using firewalls or reverse proxies to limit exposure
  • Implement strict monitoring of authentication logs and anomalous data activity to detect potential exploitation attempts

Generated by OpenCVE AI on August 19, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Partner Management Allowing Unauthorized Data Access
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Partner Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle partner Management
CPEs cpe:2.3:a:oracle:partner_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle partner Management
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Partner Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:16:40.947Z

Reserved: 2026-07-14T14:54:48.744Z

Link: CVE-2026-62605

cve-icon Vulnrichment

Updated: 2026-08-25T14:19:28.361Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:12.917

Modified: 2026-08-31T15:07:52.640

Link: CVE-2026-62605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T11:45:04Z

Weaknesses