Description
Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Internet Procurement Connector versions 12.2.3 through 12.2.15 contain a flaw that allows a low‑privileged attacker with network access via HTTP to take control of the application. The vulnerability can enable the attacker to create, delete, or modify critical data and to retrieve all data accessible by the connector. The impact is a loss of confidentiality and integrity of data handled by the product. Based on the description, the likely attack vector is the exposed HTTP interface, with the attacker only needing lower‑level network privileges and no special authentication. This is an easily exploitable weakness that grants broad data‑handling capabilities without proper authorization.

Affected Systems

Oracle Corporation’s Internet Procurement Connector, versions 12.2.3 to 12.2.15 inclusive. No other product versions or vendors are listed as affected.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high severity vulnerability, primarily due to significant confidentiality and integrity impacts while availability is unaffected. EPSS data is not available, so the exact likelihood of exploitation cannot be quantified, but the lack of a KEV listing does not reduce the risk posed by the high CVSS score. An attacker only needs network access and low privileges, making it a realistic threat for organizations exposing the connector to internal or external networks.

Generated by OpenCVE AI on August 19, 2026 at 02:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that addresses this vulnerability, which removes the flaw in the HTTP interface and restricts access to authorized functions.
  • Limit network exposure of the Oracle Internet Procurement Connector by configuring firewall rules or access control lists so that only trusted internal hosts can reach its HTTP endpoint.
  • Monitor application logs and network traffic for anomalous HTTP requests that could indicate exploitation attempts; use intrusion detection to generate alerts if suspicious activity is observed.

Generated by OpenCVE AI on August 19, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title High Impact Low‑Privilege Remote Access Vulnerability in Oracle Internet Procurement Connector
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle internet Procurement Connector
CPEs cpe:2.3:a:oracle:internet_procurement_connector:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle internet Procurement Connector
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Internet Procurement Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:01:57.979Z

Reserved: 2026-08-04T22:06:34.599Z

Link: CVE-2026-70815

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:36.210

Modified: 2026-08-18T21:17:36.210

Link: CVE-2026-70815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T02:30:03Z

Weaknesses