Description
Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Loans. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Loans, a component of Oracle E‑Business Suite, contains an improper privilege management flaw that allows a low‑privileged attacker with network access via HTTP to create, delete or modify critical data and to trigger a partial denial of service. The vulnerability enables unauthorized access to data without authentication and is classified as a CWE‑284 type weakness.

Affected Systems

Oracle Corporation’s Oracle Loans product is affected for every supported release from version 12.2.3 through 12.2.15 inclusive. Any deployment that runs one of these releases is vulnerable; versions outside this range are not known to be impacted.

Risk and Exploitability

The CVSS 3.1 Base Score of 7.1 signifies a moderate to high risk. Because no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, there is no documented public exploitation yet. The attack vector is inferred to be remote HTTP: an adversary can connect to the service over the network, bypass authentication checks, and manipulate data or trigger a partial denial of service using only the privileges granted by network access, with no additional privileges required.

Generated by OpenCVE AI on August 19, 2026 at 13:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Loans to a release newer than 12.2.15 or apply the vendor‑issued patch that addresses the privilege management flaw.
  • If an immediate patch is not yet available, restrict inbound HTTP traffic to the Oracle Loans service by placing the server behind a firewall or VPN and allowing traffic only from trusted IP ranges.
  • Enable auditing and monitor Oracle Loans logs for unexpected data modifications or service interruptions, and investigate any anomalies promptly.

Generated by OpenCVE AI on August 19, 2026 at 13:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle e-business Suite
CPEs cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:loans:-:*:*:*:*:*:*:*
Vendors & Products Oracle e-business Suite

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Exploit in Oracle Loans Allows Unauthenticated Data Manipulation

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Exploit in Oracle Loans Allows Unauthenticated Data Manipulation
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Loans. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle loans
CPEs cpe:2.3:a:oracle:loans:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle loans
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle E-business Suite Loans
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:11.511Z

Reserved: 2026-08-04T22:06:34.601Z

Link: CVE-2026-70845

cve-icon Vulnrichment

Updated: 2026-08-19T12:10:56.067Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:40.297

Modified: 2026-08-28T14:45:32.720

Link: CVE-2026-70845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T13:45:02Z

Weaknesses