PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61200 Oracle Corporation CVE debrief

A vulnerability exists in Oracle Labor Distribution, a component of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks can result in unauthorized update, insert or delete access to some accessible data and unauthorized read access to a subset of accessible data. The CVSS 3.1 Base Score is 5.4, indicating medium severity with Confidentiality and Integrity impacts.

Vendor
Oracle Corporation
Product
Oracle Labor Distribution
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Organizations using Oracle Labor Distribution within Oracle E-Business Suite versions 12.2.3-12.2.15 should prioritize patching this vulnerability. Low-privileged attackers with network access via HTTP can exploit this vulnerability, potentially leading to data tampering and information disclosure.

Technical summary

The vulnerability in Oracle Labor Distribution (component: Internal Operations) of Oracle E-Business Suite (versions 12.2.3-12.2.15) is easily exploitable. A low-privileged attacker with network access via HTTP can compromise Oracle Labor Distribution. Successful attacks can lead to unauthorized update, insert or delete access to some accessible data and unauthorized read access to a subset of accessible data. The CVSS 3.1 score is 5.4 (Confidentiality and Integrity impacts), with the vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N.

Defensive priority

Apply patches or updates provided by Oracle to address the vulnerability in Oracle Labor Distribution. Restrict network access to the affected systems and monitor for suspicious activities.

Recommended defensive actions

  • Apply patches or updates provided by Oracle to address the vulnerability in Oracle Labor Distribution.
  • Restrict network access to the affected systems.
  • Monitor for suspicious activities and implement additional security measures to protect against potential attacks.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-07-21T22:18:51.730Z and was last modified on 2026-07-22T19:17:08.307Z. The NVD entry is currently in the 'Received' status. Oracle has provided a security alert for this vulnerability (reference: https://www.oracle.com/security-alerts/cpujul2026.html).

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:51.730Z and has not been modified since then. The NVD entry is currently Received.