PatchSiren cyber security CVE debrief
CVE-2026-60697 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:10.373Z and has not been modified since then. The CVE-2026-60697 vulnerability is a medium-severity issue affecting Oracle E-Business Suite versions 12.2.3-12.2.15. It resides in the Site Hierarchy Flows component of Oracle Site Hub and allows low-privileged attackers with network access via HTTP to compromise Oracle Site Hub. Successful exploitation can lead to unauthorized data access, modification, and partial denial of service. The CVSS 3.1 Base Score is 6.3, with impacts on confidentiality, integrity, and availability. Oracle E-Business Suite administrators, security teams, and IT professionals responsible for managing and securing Oracle Site Hub should be aware of this vulnerability and take necessary actions to mitigate the risk.
- Vendor
- Oracle Corporation
- Product
- Oracle Site Hub
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-06
Who should care
Oracle E-Business Suite administrators, security teams, and IT professionals responsible for managing and securing Oracle Site Hub should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The CVE-2026-60697 vulnerability is a medium-severity issue affecting Oracle E-Business Suite versions 12.2.3-12.2.15. It resides in the Site Hierarchy Flows component of Oracle Site Hub and allows low-privileged attackers with network access via HTTP to compromise Oracle Site Hub. Successful exploitation can lead to unauthorized data access, modification, and partial denial of service. The CVSS 3.1 Base Score is 6.3, with impacts on confidentiality, integrity, and availability.
Defensive priority
Medium priority given the CVSS score of 6.3 and the potential for unauthorized data access and partial denial of service.
Recommended defensive actions
- Inventory and verify affected Oracle E-Business Suite versions
- Apply vendor patches or updates as recommended by Oracle
- Implement compensating controls to restrict network access to Oracle Site Hub
- Monitor for suspicious activity and implement logging and auditing
- Review and update security configurations for Oracle E-Business Suite
Evidence notes
The CVE-2026-60697 vulnerability affects Oracle E-Business Suite versions 12.2.3-12.2.15, specifically the Site Hierarchy Flows component of Oracle Site Hub. A low-privileged attacker with network access via HTTP can exploit this vulnerability. Successful attacks can lead to unauthorized update, insert, or delete access to some Oracle Site Hub data, unauthorized read access to a subset of Oracle Site Hub data, and partial denial of service. The CVSS 3.1 Base Score is 6.3, indicating medium severity.
Official resources
-
CVE-2026-60697 CVE record
CVE.org
-
CVE-2026-60697 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:10.373Z and has not been modified since then.