Description
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Marketing in Oracle E‑Business Suite has a vulnerability that enables a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized access to critical data or full exposure of all Oracle Marketing accessible data, resulting in a confidentiality breach. The flaw is considered easily exploitable and may cause significant impact beyond the Marketing component.

Affected Systems

The vulnerability affects Oracle Marketing versions 12.2.3 through 12.2.15. These releases are part of the Oracle E‑Business Suite and are used by organizations that rely on Marketing services.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 Base Score of 7.7 with an AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N vector, indicating high potential for confidentiality impact when accessed over the network. EPSS data is not available and the flaw is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited publicly. The likely attack vector requires network connectivity over HTTP and a low‑privileged user account, making it feasible for adversaries with limited access.

Generated by OpenCVE AI on August 19, 2026 at 11:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Oracle Marketing patch or update released for versions 12.2.3 to 12.2.15 to fix the vulnerability.
  • Restrict HTTP access to Oracle Marketing by implementing firewall rules or access control lists so that only trusted internal networks or management interfaces can reach the service.
  • Enforce least‑privilege access controls and perform periodic reviews of user permissions to prevent low‑privileged accounts from gaining unauthorized data access.
  • Monitor application and network logs for suspicious authentication attempts or data exfiltration activity related to Oracle Marketing.

Generated by OpenCVE AI on August 19, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Oracle Marketing Unauthorized Data Access Vulnerability via HTTP
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle marketing
CPEs cpe:2.3:a:oracle:marketing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle marketing
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Marketing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:58:22.741Z

Reserved: 2026-08-04T22:06:34.589Z

Link: CVE-2026-70687

cve-icon Vulnrichment

Updated: 2026-08-25T15:58:14.954Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:20.657

Modified: 2026-09-03T17:06:21.370

Link: CVE-2026-70687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T12:00:05Z

Weaknesses