Description
Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing Encyclopedia System. While the vulnerability is in Oracle Marketing Encyclopedia System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing Encyclopedia System accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An easily exploitable flaw in Oracle Marketing Encyclopedia System allows a low‑privileged attacker with network access via HTTP to compromise the system and obtain unauthorized access to critical data, potentially gaining full access to all data the application exposes. The vulnerability is not limited to this product; if exploited, it may impact additional products in the Oracle E‑Business Suite due to a scope change. The attack requires no user interaction and does not affect integrity or availability, but it does endanger confidentiality.

Affected Systems

Oracle Marketing Encyclopedia System, part of Oracle E‑Business Suite, Internal Operations component. Supported affected versions are 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS v3.1 base score of 7.7 indicates a high‑severity vulnerability driven by confidentiality impact. The EPSS score is currently unavailable, and the issue is not listed in the CISA KEV catalog. The attack vector is network‑based using HTTP; a low‑privileged attacker can exploit the flaw without authentication or privileged access, making it readily exploitable in environments where the application is exposed to the network.

Generated by OpenCVE AI on August 19, 2026 at 11:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that addresses CVE-2026-70692 as soon as it becomes available.
  • Restrict HTTP access to the Oracle Marketing Encyclopedia System to trusted IP ranges or require VPN traversal.
  • Ensure that authentication mechanisms and access controls are enforced so that only authorized users can view confidential data.
  • Monitor application and network logs for unauthorized access attempts and verify that the vulnerability has been mitigated.

Generated by OpenCVE AI on August 19, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle e-business Suite
CPEs cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:marketing_encyclopedia_system:-:*:*:*:*:*:*:*
Vendors & Products Oracle e-business Suite

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Access Enables Unauthorized Data Breach in Oracle Marketing Encyclopedia System
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Marketing Encyclopedia System product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing Encyclopedia System. While the vulnerability is in Oracle Marketing Encyclopedia System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing Encyclopedia System accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle marketing Encyclopedia System
CPEs cpe:2.3:a:oracle:marketing_encyclopedia_system:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle marketing Encyclopedia System
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle E-business Suite Marketing Encyclopedia System
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:57:52.628Z

Reserved: 2026-08-04T22:06:34.590Z

Link: CVE-2026-70692

cve-icon Vulnrichment

Updated: 2026-08-25T15:57:44.399Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:21.227

Modified: 2026-09-02T17:43:27.640

Link: CVE-2026-70692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T07:00:06Z

Weaknesses