PatchSiren

Oracle Corporation CVE debriefs · Page 16

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61293

A high-severity vulnerability (CVSS 3.1 score of 8.1) exists in Oracle Hyperion Calculation Manager, version 11.2.25.0.000. The vulnerability is difficult to exploit and allows unauthenticated attackers with network access via HTTP to potentially take over the manager. Organizations should prioritize patching this vulnerability to prevent potential takeovers. The CVE record was published on 2026-08-18T21: [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61291

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:58.290Z and has not been modified since then. The CVE-2026-61291 vulnerability in Oracle WebCenter Content allows low-privileged attackers with logon to the infrastructure to compromise Oracle WebCenter Content. The CVSS 3.1 Base Score is 7.8, indicating a high severity impact. This vulnera [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61288

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:58.050Z and has not been modified since then. The vulnerability affects Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, allowing unauthenticated attackers to compromise data confidentiality and integrity via HTTP. Human interaction is required for successful attacks. Organizati [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61284

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:57.810Z and has not been modified since then. This vulnerability affects Oracle Enterprise Manager Base Platform, specifically versions 13.5 and 24.1, within the Application Config Console component. It is characterized as an easily exploitable vulnerability that allows a low-privileged att [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-61272

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:57.340Z and has not been modified since then. The vulnerability in JD Edwards EnterpriseOne Tools (component: Web Runtime SEC) allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to full takeover. Successful attacks can result in takeo [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61270

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:57.223Z and has not been modified since then. This vulnerability affects JD Edwards EnterpriseOne Orchestrator versions 9.2.0.0-9.2.26.4, with a CVSS 3.1 Base Score of 8.1, indicating high severity. The vulnerability is easily exploitable by low-privileged attackers with network access via [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61268

The CVE-2026-61268 vulnerability affects Oracle JD Edwards EnterpriseOne Tools, specifically the Business Logic Infra SEC component. This vulnerability has a CVSS 3.1 Base Score of 8.1, indicating high severity. It allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. Organizations sh [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61265

The CVE-2026-61265 vulnerability affects the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards, specifically the E1 IOT Orchestrator Security component. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via TLS to potentially take over the Orchestrator. The vulnerability has a CVSS 3.1 Base Score of 8.1, indicating high severity. Organizations sh [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61259

The CVE-2026-61259 vulnerability affects the Oracle Hyperion Calculation Manager product, specifically the Security component. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can lead to unauthorized access to critical data and partial denial of service. The CVSS 3.1 Base Score is 7.1, indicating high s [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61229

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:56.130Z and has not been modified since then. The CVE-2026-61229 vulnerability affects Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0, with a CVSS score of 8.1, indicating high confidentiality, integrity, and availability impacts. This vulnerability allows unauthenticated attack [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61228

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:56.000Z and has not been modified since then. The CVE-2026-61228 vulnerability is in the Oracle WebCenter Portal product of Oracle Fusion Middleware, specifically in the Runtime Tools component. It affects versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability has a CVSS score of 8.6 and all [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61227

The CVE-2026-61227 vulnerability is a highly critical issue in Oracle WebCenter Portal, a component of Oracle Fusion Middleware. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Portal. It allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data or complete access to all Oracle WebCen [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61219

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:55.660Z and has not been modified since then. CVE-2026-61219 is a vulnerability in Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It allows low-privileged attackers with network access via HTTP to compromise the system, with a CVSS score of 8.7. Successful attacks re [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61215

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:55.543Z and has not been modified since then. The CVE-2026-61215 vulnerability affects Oracle WebCenter Portal, allowing low-privileged attackers with network access via HTTP to compromise the system. Successful attacks require human interaction and can result in unauthorized creation, dele [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61213

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:55.427Z and has not been modified since then. The CVE-2026-61213 vulnerability is an easily exploitable issue in Oracle WebCenter Portal, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover of Oracle WebCenter Portal. The [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61212

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:55.310Z and has not been modified since then. The CVE-2026-61212 vulnerability affects Oracle WebCenter Portal, allowing low-privileged attackers with network access via HTTP to compromise the system. The vulnerability has a high CVSS score of 8.5, indicating high confidentiality, integrity [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-61206

CVE-2026-61206 is a critical vulnerability in Oracle Hyperion Calculation Manager, a component of Oracle Hyperion. The vulnerability has a CVSS score of 9.9, indicating a high severity level. It allows a low-privileged attacker with network access via HTTP to compromise the manager, potentially impacting additional products. The supported version affected is 11.2.25.0.000. Oracle Hyperion Calculation Mana [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61199

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:54.893Z and has not been modified since then. CVE-2026-61199 is a vulnerability in Oracle WebCenter Portal (Runtime Tools). A low-privileged attacker with network access via HTTP can exploit this vulnerability to compromise Oracle WebCenter Portal and access critical data. The vulnerability [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-61198

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:54.770Z and has not been modified since then. The vulnerability in Oracle Learning Management (component: Internal Operations) allows unauthenticated attackers with network access via HTTP to compromise Oracle Learning Management. This can lead to unauthorized update, insert or delete acces [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61193

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:54.653Z and has not been modified since then. The CVE-2026-61193 vulnerability is a difficult-to-exploit vulnerability in Oracle WebCenter Portal that allows unauthenticated attackers with network access via HTTP to compromise the system and impact additional products. Successful attacks ca [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61177

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:54.537Z and has not been modified since then. The CVE-2026-61177 vulnerability affects Oracle WebCenter Portal, a component of Oracle Fusion Middleware, specifically impacting versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability is exploitable by low-privileged attackers with network acce [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-61139

The CVE-2026-61139 vulnerability affects Oracle Public Sector Financials (International) versions 12.2.3-12.2.15, with a CVSS 3.1 score of 6.3, indicating medium severity. The vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, leading to unauthorized update, insert, or delete access to some accessible data, unauthorized read access to a subset of accessibl [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61058

CVE-2026-61058 is a vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. The vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the system. This could potentially lead to a takeover of Oracle WebCenter Sites. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Sites and ha [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61054

CVE-2026-61054 is a vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0, allowing unauthenticated attackers with network access via HTTP to compromise the site. Successful attacks can lead to unauthorized access to critical data and update, insert, or delete access to some data. The CVSS score is 8.2, indicating hig [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61038

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:53.340Z and has not been modified since then. CVE-2026-61038 is a high-severity vulnerability in Oracle WebCenter Sites, allowing unauthenticated attackers to access critical data with a CVSS score of 8.2. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0, and successful attacks [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-61034

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:53.220Z and has not been modified since then. The CVE-2026-61034 vulnerability is a critical severity issue in Oracle WebCenter Sites, allowing high privileged attackers with network access via HTTP to compromise the system, potentially impacting additional products. The vulnerability has a [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61032

The CVE-2026-61032 vulnerability is an easily exploitable issue in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. This vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover of Oracle WebCenter Sites. The CVE record was published on 2026-08-18T21:16:52.987Z and has not been modified since then. Affected version [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-61029

The CVE-2026-61029 vulnerability is a critical issue in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Sites, potentially impacting additional products. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. The vulnerability has a CVSS score of 9.0, indicati [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61022

The CVE-2026-61022 vulnerability is an easily exploitable issue in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. This vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover of Oracle WebCenter Sites. The vulnerability affects Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 and has a CVSS score of 8.8 [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-61021

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:52.607Z and has not been modified since then. The CVE-2026-61021 vulnerability affects Oracle WebCenter Sites, allowing low-privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in takeover of Oracle WebCenter Sites. The vulnerability has [truncated]