PatchSiren

Oracle Corporation CVE debriefs · Page 13

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70899

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:47.587Z and has not been modified since then. The CVE-2026-70899 vulnerability affects Oracle Hyperion Data Relationship Management, version 11.2.25.0.000, and is an easily exploitable vulnerability that allows low-privileged attackers with network access via HTTP to compromise the system. [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70898

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:47.470Z and has not been modified since then. The Oracle Hyperion Data Relationship Management product has a vulnerability in the Access and security component. The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with n [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70897

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:47.357Z and has not been modified since then. The CVE-2026-70897 vulnerability affects Oracle Hyperion Data Relationship Management version 11.2.25.0.000, allowing an unauthenticated attacker with network access via HTTPS to compromise the product. Successful attacks can result in unauthori [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70896

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:47.237Z and has not been modified since then. Vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated attacker with network access via HTTP to compromise the data. CVSS score of 7.5 indicates high severity. The supported version that is affected is 11.2.25.0.000 [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70895

The CVE-2026-70895 vulnerability is a critical security issue in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. This vulnerability allows a low-privileged attacker with logon access to compromise Oracle Hyperion Data Relationship Management, potentially impacting additional products. Suc [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70894

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:46.993Z and has not been modified since then. Vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated attacker with logon to compromise the system, potentially leading to unauthorized creation, deletion or modification access to critical data. This vulnerability [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70893

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:46.060Z and has not been modified since then. The vulnerability in Oracle Hyperion Data Relationship Management allows a low privileged attacker with network access via SQL to compromise the product. Successful attacks can result in unauthorized creation, deletion or modification access to [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70892

The CVE-2026-70892 vulnerability is a difficult-to-exploit issue in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. This vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Ora [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70891

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:45.817Z and has not been modified since then. The vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated attackers with network access via HTTP to compromise Oracle. This can lead to unauthorized access to critical data or complete access to all Oracle Hyperion [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70890

The CVE record for CVE-2026-70890 was published on 2026-08-18T21:17:45.693Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This high-severity vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated attackers with network access via HTTP to compromise data confidentiality. The CVSS score is 7.5, indicating high severity, with potential for [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70889

The CVE-2026-70889 vulnerability affects Oracle Hyperion Data Relationship Management version 11.2.25.0.000, an easily exploitable vulnerability allowing unauthenticated attackers with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. The CVSS 3.1 B [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70888

The CVE-2026-70888 vulnerability affects Oracle Hyperion Data Relationship Management, specifically version 11.2.25.0.000. This vulnerability is difficult to exploit and allows high privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in takeover of Oracle Hyperion Data Relationship Management. The CVSS score is 6.6, indicating a medium severity level. [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70859

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:42.117Z and has not been modified since then. The CVE-2026-70859 vulnerability affects Siebel CRM Integration product of Oracle Siebel CRM, with a CVSS score of 8.5. The vulnerability is difficult to exploit and allows low privileged attacker with network access via HTTP to compromise Siebe [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70857

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:41.867Z and has not been modified since then. The vulnerability affects Siebel CRM End User versions 17.0-26.6 and has a CVSS 3.1 Base Score of 7.7, indicating high confidentiality and integrity impacts. Organizations should verify their deployments and apply patches or mitigations as neces [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70856

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:41.737Z and has not been modified since then. The vulnerability, CVE-2026-70856, is a high-severity issue in Siebel CRM Deployment, with a CVSS score of 7.5. It allows unauthenticated attackers with network access via HTTP to potentially take over the deployment, but requires human interact [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-70855

The CVE-2026-70855 vulnerability affects Siebel Apps - Self Service, a component of Oracle Siebel CRM. This vulnerability is classified as critical, with a CVSS 3.1 score of 9.3, indicating high confidentiality and integrity impacts. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise the application, potentially impacting additional products. Successful attacks r [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70789

The CVE-2026-70789 vulnerability in Oracle Hyperion Financial Reporting 11.2.25.0.000 is a difficult-to-exploit vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting ac [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70772

The CVE-2026-70772 vulnerability in Oracle Warehouse Management is an easily exploitable vulnerability that allows unauthenticated attackers with network access via HTTP to compromise the system and access critical data. The affected versions are 12.2.3-12.2.15, and the CVSS score is 7.5. Organizations should be aware of this vulnerability and take steps to mitigate it. This vulnerability has a significan [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70771

The CVE-2026-70771 vulnerability in Oracle Warehouse Management, a component of Oracle E-Business Suite, is a high-severity issue that allows a low-privileged attacker with network access via HTTPS to compromise the system. The vulnerability has a CVSS score of 7.7 and can result in unauthorized access to critical data or complete access to all Oracle Warehouse Management accessible data. Organizations us [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70770

CVE-2026-70770 is a high-severity vulnerability in Oracle Warehouse Management, a component of Oracle E-Business Suite. The vulnerability is classified as easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise the system. This could lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or comple [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70766

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:29.300Z and has not been modified since then. The vulnerability in Oracle Hyperion Financial Reporting (component: Server) allows an unauthenticated attacker with network access via HTTP to compromise the system, potentially leading to unauthorized update, insert or delete access to some ac [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70765

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:29.183Z and has not been modified since then. The vulnerability in Oracle Hyperion Financial Reporting (component: Server) allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks require human interaction and can result in unauthorized upda [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70763

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:28.943Z and has not been modified since then. The CVE-2026-70763 vulnerability is in the Oracle Operations Intelligence product of Oracle E-Business Suite, specifically in the Daily Business Intelligence component. Versions 12.2.3 through 12.2.15 are affected. The vulnerability is difficult [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70762

The CVE-2026-70762 vulnerability affects Oracle Risk Management in Oracle E-Business Suite, versions 12.2.3-12.2.15. This vulnerability is exploitable over HTTP by low-privileged attackers, potentially leading to unauthorized data access and modification. The CVSS score of 8.1 indicates high severity. Organizations using affected versions should prioritize patching and review access controls.

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70761

The CVE-2026-70761 vulnerability affects Oracle Risk Management versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. This vulnerability has a CVSS 3.1 Base Score of 8.8, indicating high severity. Organizations should prioritize patching to prevent potential security breaches. The CVE record was published on 2026- [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70760

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:28.593Z and has not been modified since then. The CVE-2026-70760 vulnerability is a difficult to exploit issue in Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). It affects versions 12.2.3-12.2.15 and allows low privileged attackers with net [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70743

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:27.113Z and has not been modified since then. CVE-2026-70743 is a vulnerability in Oracle Hyperion Financial Reporting product, specifically in the Server component. The affected version is 11.2.25.0.000. This vulnerability allows unauthenticated attackers with network access via HTTPS to c [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70738

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:26.553Z and has not been modified since then. Vulnerability in Oracle Hyperion Profitability and Cost Management, allowing low privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management, with potential for unauthorized creation, deletion [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70737

A vulnerability in Oracle Enterprise Manager for Systems Infrastructure allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. Oracle Corporation has released an advisory addressing this issue. The vulnerability affects versions 13.5 and 24.1, and its high severity is underscored by a CVSS score of 8.8, indicating significant confidentiality [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70709

The CVE-2026-70709 vulnerability affects Oracle Agile Engineering Data Management, specifically the Engineering Communication Interface component. This medium-severity vulnerability, with a CVSS score of 4.8, allows unauthenticated attackers with network access via HTTP to potentially update, insert or delete some accessible data and read a subset of accessible data. Organizations using Oracle Agile Engin [truncated]