Description
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSupplier Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle iSupplier Portal enables attackers who can reach the service via HTTP to create, delete, or modify critical data without authentication. The vulnerability results in confidentiality and integrity breaches for all data that the portal exposes. The attack requires no privileged credentials, lowering the barrier to exploitation.

Affected Systems

Vulnerable versions are Oracle iSupplier Portal 12.2.3 through 12.2.15, part of the Oracle E‑Business Suite Internal Operations component. The vulnerability affects installations that expose the portal’s HTTP interface to a network, whether internally or externally.

Risk and Exploitability

The CVSS base score of 7.4 reflects high confidentiality and integrity impact, and the attack vector is network based but requires unauthenticated access over HTTP. Based on the description, it is inferred that the exploit requires moderate technical skill and network reachability. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation but still posing a significant risk in exposed environments.

Generated by OpenCVE AI on August 24, 2026 at 23:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle updates that address the iSupplier Portal 12.2.3 through 12.2.15 versions.
  • If no update is available, block HTTP traffic to the portal from untrusted networks using firewalls or ACLs.
  • Enable detailed logging and real‑time monitoring to detect unauthorized data operations on the portal.

Generated by OpenCVE AI on August 24, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification in Oracle iSupplier Portal

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification in Oracle iSupplier Portal
Weaknesses CWE-306

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Manipulation in Oracle iSupplier Portal
Weaknesses CWE-284
CWE-287

Wed, 19 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Manipulation in Oracle iSupplier Portal
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSupplier Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle isupplier Portal
CPEs cpe:2.3:a:oracle:isupplier_portal:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isupplier Portal
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Isupplier Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:22:50.863Z

Reserved: 2026-08-04T22:06:34.596Z

Link: CVE-2026-70779

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:55.113Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:31.073

Modified: 2026-08-26T17:40:55.747

Link: CVE-2026-70779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:15:04Z

Weaknesses