PatchSiren

Oracle CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61195

A vulnerability was discovered in Oracle Agile Engineering Data Management, a product of Oracle Supply Chain. The affected component is Core, and the supported version that is affected is 6.2.1. This vulnerability allows a low-privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful attacks can result in unauthorized ability to cause a hang or freq [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61192

A medium-severity vulnerability was found in Oracle Agile Engineering Data Management, specifically in the Install component. This vulnerability, tracked as CVE-2026-61192, has a CVSS score of 5.3 and can allow a low-privileged attacker with network access via HTTP to compromise the system, leading to a denial of service (complete DOS). The vulnerability is difficult to exploit and affects version 6.2.1 o [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61191

A vulnerability was discovered in Oracle Agile Engineering Data Management, specifically in the Document Management component. The affected version is 6.2.1. This vulnerability is easily exploitable by a low-privileged attacker with logon access to the infrastructure where Oracle Agile Engineering Data Management executes. Successful attacks can result in unauthorized update, insert or delete access to so [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61190

A medium-severity vulnerability was found in Oracle Agile Engineering Data Management, specifically in the Install component. This vulnerability, tracked as CVE-2026-61190, has a CVSS score of 6.4 and can allow a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks require human interaction and can lead to unauthorized creation, deletion, or modification of cri [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61189

A medium-severity vulnerability was found in Oracle Agile Engineering Data Management, a product within Oracle Supply Chain. The issue, tracked as CVE-2026-61189, has a CVSS score of 6.5 and allows low-privileged attackers with logon access to compromise the system, potentially impacting additional products. The vulnerability is in the Install component of version 6.2.1. Successful attacks can result in u [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-61187

A vulnerability was discovered in Oracle Agile Engineering Data Management, specifically in the Install component. The affected version is 6.2.1. This vulnerability allows a low-privileged attacker with logon access to the infrastructure where Oracle Agile Engineering Data Management executes to compromise the product. Successful attacks require human interaction from another person. The impact of a succe [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61186

A critical vulnerability was discovered in Oracle Agile Engineering Data Management, a product of Oracle Supply Chain. The vulnerability affects version 6.2.1 and allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, unauthorized read access to a subset of accessible data [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61176

The CVE-2026-61176 vulnerability affects Oracle Product Lifecycle Analytics version 3.6.1, allowing high-privileged attackers with network access via HTTP to compromise the system. This vulnerability has a medium severity with a CVSS score of 6.7, indicating potential unauthorized data access, modification, and partial denial of service. Oracle Product Lifecycle Analytics users and administrators should b [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61175

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:49.290Z and has not been modified since then. The CVE-2026-61175 vulnerability in Oracle Product Lifecycle Analytics 3.6.1 allows unauthenticated attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks can result in una [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61174

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:49.170Z and has not been modified since then. The CVE-2026-61174 vulnerability is in Oracle Product Lifecycle Analytics 3.6.1, with a CVSS score of 9.0. It allows unauthenticated attackers with logon access to compromise Oracle Product Lifecycle Analytics, potentially impacting additional p [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61165

The CVE-2026-61165 vulnerability in Oracle Commerce Guided Search Platform Services, a component of Oracle Commerce, allows low-privileged attackers with network access via HTTP to compromise the service. This vulnerability, affecting version 11.4.0, could lead to a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search Platform Services and unauthorized read access to a subse [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61156

The CVE-2026-61156 vulnerability in Oracle Commerce Guided Search Platform Services, a component of Oracle Commerce, has been identified as critical. This vulnerability, classified under the Forge component, allows unauthenticated attackers with network access via HTTPS to compromise the service. The potential impacts include unauthorized creation, deletion, or modification of critical data. Users are adv [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61155

CVE-2026-61155 is a critical vulnerability in the Forge component of Oracle Commerce Guided Search Platform Services, specifically affecting version 11.4.0. The vulnerability has a CVSS score of 9.1, indicating a high severity level. It allows unauthenticated attackers with network access via HTTP to potentially gain unauthorized access to critical data and cause a complete denial of service (DOS) of the [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61154

The CVE-2026-61154 record indicates a critical vulnerability in Oracle Commerce Guided Search Platform Services, specifically in the Forge component. The vulnerability has a CVSS score of 9.8 and can be easily exploited by unauthenticated attackers with network access via HTTP, potentially leading to a complete takeover of the service. The affected version is 11.4.0. Oracle Commerce Guided Search Platform [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61137

A high-severity vulnerability was discovered in Oracle Commerce Platform. This vulnerability, tracked as CVE-2026-61137, has a CVSS score of 8.1 and can allow an unauthenticated attacker with network access via HTTP to compromise the platform, potentially leading to a takeover. The vulnerability is located in the Dynamo Application Framework component of Oracle Commerce Platform. The supported version tha [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61136

A high-severity vulnerability was discovered in Oracle Commerce Platform's Dynamo Application Framework component. The vulnerability is easily exploitable, allowing unauthenticated attackers to compromise the platform via HTTP, potentially leading to unauthorized data access and partial denial of service. Security teams and administrators should be aware and take immediate action.

HIGH Oracle CVE published 2026-07-21

CVE-2026-61135

A high-severity vulnerability was discovered in Oracle Commerce Platform, specifically in the Dynamo Application Framework component. This vulnerability, tracked as CVE-2026-61135, has a CVSS score of 7.4 and can allow unauthenticated attackers with network access via HTTP to compromise the platform. Successful attacks can result in unauthorized creation, deletion, or modification of critical data. The vu [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61134

A medium-severity vulnerability was found in Oracle Commerce Platform's Dynamo Application Framework component. The vulnerability has a CVSS score of 6.8 and can allow low-privileged attackers with network access via HTTP to compromise the platform, leading to unauthorized creation, deletion, or modification of critical data. Organizations should prioritize patching to prevent potential data breaches. The [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61133

A high-severity vulnerability was found in Oracle Commerce Platform, specifically in the Dynamo Application Framework component of version 11.4.0. The vulnerability has a CVSS score of 7.5 and can allow unauthenticated attackers with network access via LDAP to access critical data. This could lead to significant data breaches if not addressed promptly. Administrators and security teams responsible for Ora [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61132

A vulnerability was discovered in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker and while [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61131

A critical vulnerability was discovered in Oracle Commerce Platform, specifically in the Dynamo Application Framework component. This vulnerability, tracked as CVE-2026-61131, has a CVSS 3.1 Base Score of 9.8, indicating a high impact on confidentiality, integrity, and availability. The vulnerability is easily exploitable by unauthenticated attackers with network access via HTTP, potentially leading to a [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61130

A critical vulnerability was discovered in Oracle Commerce Platform, specifically in the Dynamo Application Framework component of version 11.4.0. The vulnerability is easily exploitable and allows unauthenticated attackers to compromise the platform, potentially leading to unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data, as well as the ability to ca [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61129

A critical vulnerability was discovered in Oracle Commerce Platform, specifically in the ATG Portals component of version 11.4.0. The vulnerability has a CVSS score of 9.8 and can be exploited by unauthenticated attackers with network access via HTTP, potentially leading to a takeover of the platform. This vulnerability is easily exploitable and has high impacts on Confidentiality, Integrity, and Availabi [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61115

The CVE-2026-61115 vulnerability affects Oracle Order Management, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing high privileged attackers with network access via HTTP to compromise Oracle Order Management, potentially leading to its takeover. The CVSS score for this vulnerability is 7.2, indicating high severity. Oracle Order Management versions 1 [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61114

The CVE-2026-61114 vulnerability affects Oracle Application Object Library, a component of Oracle E-Business Suite. This difficult-to-exploit vulnerability allows low privileged attackers with network access via HTTP to compromise the library, potentially leading to takeover. Organizations should prioritize patching to prevent potential security breaches. The CVSS 3.1 Base Score is 7.5, indicating high severity.

HIGH Oracle CVE published 2026-07-21

CVE-2026-61113

CVE-2026-61113 is a high-severity vulnerability in Oracle Application Object Library versions 12.2.3-12.2.15. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the library, potentially leading to unauthorized creation, deletion, or modification of critical data or complete access to all Oracle Application Object Library accessible data. The CVSS score is 7.4, i [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61112

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:42.483Z and has not been modified since then. The CVE-2026-61112 vulnerability is in the Oracle Order Management product of Oracle E-Business Suite, specifically in the Product Diagnostic Tools component. The vulnerability has a CVSS score of 6.5 and is considered easily exploitable, allowi [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61111

The CVE-2026-61111 vulnerability is a medium-severity issue affecting Oracle Application Object Library versions 12.2.3-12.2.15. It allows low-privileged attackers with logon access to compromise the library, potentially impacting additional products. The CVSS 3.1 Base Score is 6.5, indicating a medium severity. Successful attacks of this vulnerability can result in unauthorized access to critical data or [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61090

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:39.997Z and has not been modified since then. Vulnerability in Oracle Project Foundation of Oracle E-Business Suite; easily exploitable, allows low-privileged attacker with logon to compromise Oracle Project Foundation; CVSS 3.1 score 7.8. Affected versions are 12.2.3-12.2.15. The vulnerabi [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61075

A vulnerability was discovered in Oracle Self-Service Human Resources, a component of Oracle E-Business Suite. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access to a subset of accessible [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61067

A high-severity vulnerability was discovered in Oracle Access Manager, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-61067, affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Access Manager. It is categorized under the component Authentication Engine. The vulnerability has a CVSS 3.1 Base Score of 8.0, indicating high impacts on Confidentiality, Integrity, and Availabilit [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-61065

A critical vulnerability was discovered in Oracle Access Manager, a product of Oracle Fusion Middleware. The vulnerability is located in the Authentication Engine component and affects versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Access Manager, potentially leading to a takeover of the system. T [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61050

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:35.843Z and has not been modified since then. The CVE-2026-61050 vulnerability is in the User Interface component of Oracle Production Scheduling in Oracle E-Business Suite versions 12.2.3-12.2.15. This medium-severity vulnerability (CVSS score of 5.3) is difficult to exploit and requires l [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61049

The CVE-2026-61049 vulnerability is a difficult-to-exploit issue in the Oracle Production Scheduling product of Oracle E-Business Suite, specifically in the Internal Operations component. Versions 12.2.3-12.2.15 are affected. The vulnerability has a CVSS score of 7.1 and a vector of CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H. It requires human interaction from a person other than the attacker and allows [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-61023

A vulnerability exists in Oracle Inventory Management, a component of Oracle E-Business Suite. The vulnerability is difficult to exploit and requires a high privileged attacker with logon to the infrastructure where Oracle Inventory Management executes. Successful attacks can result in takeover of Oracle Inventory Management. This vulnerability affects Oracle Inventory Management versions 12.2.3-12.2.15 a [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61020

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:33.573Z and has not been modified since then. The CVE-2026-61020 vulnerability affects Oracle Customers Online, a component of Oracle E-Business Suite, specifically versions 12.2.3-12.2.15. It is an easily exploitable vulnerability that allows low-privileged attackers with network access vi [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61019

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:33.467Z and has not been modified since then. CVE-2026-61019 is a high-severity vulnerability in Oracle Customers Online, with a CVSS score of 8.1. It allows low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. Affected versions include 12. [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61014

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:33.243Z and has not been modified since then. CVE-2026-61014 is a high-severity vulnerability in Oracle Inventory Management, a component of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and allows low-privileged attackers with network access via HTTP to comprom [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60999

The CVE-2026-60999 vulnerability affects Oracle Data Integrator version 14.1.2.0.0, allowing unauthenticated attackers with network access via HTTPS to compromise the system. This vulnerability has a CVSS 3.1 Base Score of 9.8, indicating high impacts on Confidentiality, Integrity, and Availability. Organizations should prioritize patching to prevent potential system takeovers. The CVE record was publishe [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60987

CVE-2026-60987 is a vulnerability in Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. The vulnerability class is related to internal operations and allows low-privileged attackers with network access via HTTP to compromise the system. The likely operational impact includes unauthorized creation, deletion, or modification access to critical data or all Oracle Project Portfolio Ana [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60986

The CVE-2026-60986 vulnerability affects Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the system. The potential impact includes unauthorized creation, deletion, or modification access to critical data or all Oracle Project Portfolio Analysis acc [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60984

CVE-2026-60984 is a vulnerability in Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 7.1 and can be exploited by low-privileged attackers with network access via HTTP, potentially leading to unauthorized data modifications or access. Organizations should review their deployments and apply patches from Oracle. The CVE record was published on [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60978

The CVE-2026-60978 vulnerability affects the Oracle Scripting product of Oracle E-Business Suite, specifically versions 12.2.3-12.2.15. This vulnerability is classified as easily exploitable, allowing high privileged attackers with network access via HTTP to compromise Oracle Scripting. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60963

CVE-2026-60963 is a high-severity vulnerability affecting Oracle E-Business Suite, specifically the Oracle Treasury component. This vulnerability has a CVSS score of 8.1 and can be exploited by a low-privileged attacker with network access via HTTP. The vulnerability allows for unauthorized creation, deletion, or modification access to critical data or all Oracle Treasury accessible data, as well as unaut [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60953

The CVE-2026-60953 vulnerability is an easily exploitable issue in Oracle Telecommunications Billing Integrator, a component of Oracle E-Business Suite. This vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data or complete access to all Oracle Telecommunications Billing [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60948

The CVE-2026-60948 vulnerability affects Oracle Learning Management, a component of Oracle E-Business Suite. This vulnerability, classified under internal operations, allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can lead to unauthorized creation, deletion, or modification access to critical data or all Oracle Learning Management accessible data, [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60945

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:29.263Z and has not been modified since then. The CVE-2026-60945 vulnerability is in the Oracle Learning Management product of Oracle E-Business Suite, specifically in the Internal Operations component. It affects versions 12.2.3-12.2.15 and has a CVSS 3.1 Base Score of 7.3, indicating high [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60943

The CVE-2026-60943 vulnerability is a difficult-to-exploit vulnerability in Oracle Service Fulfillment Manager that allows low privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in takeover of Oracle Service Fulfillment Manager. The vulnerability has a CVSS 3.1 Base Score of 7.5 and affects Oracle Service Fulfillment Manager versions 12.2.3-12.2.15. [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60942

The CVE-2026-60942 vulnerability is an easily exploitable issue in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks of this vulnerability can re [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60939

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:28.660Z and has not been modified since then. The CVE-2026-60939 vulnerability affects Oracle Project Contracts versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the product and gain unauthorized read access to a subset of accessible data. [truncated]