PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60571 Oracle Corporation CVE debrief

A vulnerability was found in Oracle SDP Number Portability product of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle SDP Number Portability accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SDP Number Portability. The CVE record was published on 2026-07-21T22:17:57.373Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.

Vendor
Oracle Corporation
Product
Oracle SDP Number Portability
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Users of Oracle SDP Number Portability product of Oracle E-Business Suite, version 12.2.3-12.2.15, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes applying patches, restricting network access, and monitoring the system for suspicious activity. Affected operators, platform administrators, vulnerability management teams, and security teams should prioritize this vulnerability based on its CVSS score and potential impact.

Technical summary

The vulnerability has a CVSS 3.1 Base Score of 5.4, with Integrity and Availability impacts. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L). This vulnerability affects Oracle SDP Number Portability product of Oracle E-Business Suite, versions 12.2.3-12.2.15. A low-privileged attacker with network access via HTTP can compromise Oracle SDP Number Portability, leading to unauthorized update, insert or delete access to some of Oracle SDP Number Portability accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SDP Number Portability.

Defensive priority

Medium

Recommended defensive actions

  • Apply the necessary patches as provided by Oracle.
  • Restrict network access to the Oracle SDP Number Portability product.
  • Monitor the system for any suspicious activity.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record was published on 2026-07-21T22:17:57.373Z and was last modified on 2026-07-27T16:18:06.473Z. The NVD entry is currently Awaiting Analysis. This information is based on the CVE record and NVD entry. Further verification is recommended.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:57.373Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.