PatchSiren

Oracle Corporation CVE debriefs · Page 17

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-61018

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:52.480Z and has not been modified since then. CVE-2026-61018 is a critical vulnerability in Oracle WebCenter Sites, allowing unauthenticated attackers with network access via HTTP to compromise the site. Successful attacks can result in takeover of Oracle WebCenter Sites. The vulnerability [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61017

The CVE-2026-61017 vulnerability is an easily exploitable issue in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. This vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover of Oracle WebCenter Sites. The CVE record was published on 2026-08-18T21:16:52.363Z and has not been modified since then. Affected version [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-61008

CVE-2026-61008 is a critical vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system. It affects supported versions 12.2.1.4.0 and 14.1.2.0.0, with a CVSS score of 9.1 impacting confidentiality and integrity. Organizations should prioritize patching to prevent unauthorized acc [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61007

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:51.887Z and has not been modified since then. The CVE-2026-61007 vulnerability is an easily exploitable issue in Oracle WebCenter Sites, allowing unauthenticated attackers with network access via HTTP to compromise the system and access critical data. The CVSS 3.1 Base Score is 7.5, indicat [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-61002

The CVE-2026-61002 vulnerability affects the Oracle SOA Suite product of Oracle Fusion Middleware, specifically the B2B Engine component. This vulnerability is easily exploitable and allows low-privileged attackers with network access via HTTP to compromise Oracle SOA Suite, potentially leading to takeover. The CVSS score for this vulnerability is 8.8, indicating a high severity. Oracle SOA Suite versions [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60996

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:51.277Z and has not been modified since then. The vulnerability in Oracle Identity Manager Connector allows high privileged attackers with network access via HTTPS to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. This vulner [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-60995

CVE-2026-60995 is a critical vulnerability in Oracle Identity Manager Connector, a component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0, allowing a low-privileged attacker with network access via TLS to potentially take over the product. Organizations should review their deployments and prioritize patching to prevent potential takeovers. The CVE record was pu [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60994

CVE-2026-60994 is a high-severity vulnerability in Oracle Identity Manager Connector, a component of Oracle Fusion Middleware. The vulnerability, classified under the Core component, affects versions 12.2.1.4.0 and 14.1.2.1.0. It is a difficult-to-exploit vulnerability that requires low privileges and human interaction to compromise the Oracle Identity Manager Connector. Successful exploitation could lead [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60983

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:50.447Z and has not been modified since then. This vulnerability affects Oracle WebCenter Content, specifically versions 14.1.2.0.0 and 12.2.1.4.0, and allows low-privileged attackers with network access via HTTP to compromise data confidentiality. The vulnerability has a CVSS 3.1 score of [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-60977

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:50.097Z and has not been modified since then. The CVE-2026-60977 vulnerability is a critical issue in Oracle WebLogic Server, allowing unauthenticated attackers with network access via RMI to compromise the server. The vulnerability has a CVSS score of 9.8 and affects versions 12.2.1.4.0, 1 [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60976

The CVE-2026-60976 vulnerability is in the Oracle Scripting product of Oracle E-Business Suite, specifically affecting versions 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Scripting, potentially leading to takeover. The CVSS score of 8.8 indicates high severity. Oracle E-Business Suite customers should prioritize patching the Oracle [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60975

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:49.840Z and has not been modified since then. The vulnerability, CVE-2026-60975, is in PeopleSoft Enterprise PeopleTools, specifically affecting versions 8.61 and 8.62. Difficult to exploit, it allows low-privileged attackers with logon access to compromise PeopleSoft Enterprise PeopleTools [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-60971

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:49.727Z and has not been modified since then. The CVE-2026-60971 vulnerability is a critical issue in Oracle WebCenter Enterprise Capture, allowing unauthenticated attackers with network access via T3 or IIOP to compromise the product. Successful attacks can result in takeover of Oracle Web [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-60958

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:49.157Z and has not been modified since then. CVE-2026-60958 is a critical vulnerability in Oracle WebCenter Enterprise Capture, allowing unauthenticated attackers with network access via HTTP to compromise the product. Successful attacks can result in takeover of Oracle WebCenter Enterpris [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60956

The CVE-2026-60956 vulnerability affects Oracle JD Edwards EnterpriseOne US Payroll version 9.2, a low-privileged attacker with network access via JDENET can potentially takeover the system. This CVE was published on 2026-08-18T21:16:49.037Z and has not been modified since then. The CVSS 3.1 score is 7.5, indicating high severity. Evidence is limited, and defenders should verify system configurations and [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60949

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:48.667Z and has not been modified since then. This vulnerability affects Oracle WebCenter Content, a component of Oracle Fusion Middleware, specifically the Content Server. The vulnerability is difficult to exploit and allows a low-privileged attacker with network access via HTTP to comprom [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-60947

CVE-2026-60947 is a critical vulnerability in the Oracle WebCenter Enterprise Capture product's Client Bundle component. This vulnerability allows unauthenticated attackers with network access via RMI to compromise the product, potentially leading to takeover. The affected versions are 12.2.1.4.0 and 14.1.2.0.0, with a CVSS score of 9.8 indicating critical severity. Organizations should prioritize patchin [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-60946

CVE-2026-60946 is a critical vulnerability in Oracle WebCenter Enterprise Capture, allowing unauthenticated attackers with network access via RMI to compromise the product. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0, with a CVSS score of 9.8, indicating high severity. Successful attacks can result in takeover of Oracle WebCenter Enterprise Capture. Evidence of exploitation is limited, an [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60944

The CVE-2026-60944 vulnerability is an easily exploitable issue in Oracle WebCenter Content that allows unauthenticated attackers with network access via HTTP to compromise the product. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauth [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60934

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:48.087Z and has not been modified since then. The vulnerability affects Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, allowing unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks can result in unauthorized creation [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60933

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:47.973Z and has not been modified since then. This vulnerability affects Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, allowing unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modifica [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60928

The CVE-2026-60928 vulnerability is a critical issue in the Oracle WebCenter Content product of Oracle Fusion Middleware, specifically in the Content Server component. This vulnerability allows a low-privileged attacker with logon access to the infrastructure where Oracle WebCenter Content executes to compromise the system. The supported version affected is 14.1.2.0.0. Successful attacks can lead to unaut [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-60921

CVE-2026-60921 is a critical vulnerability in Oracle WebCenter Enterprise Capture, allowing unauthenticated attackers to compromise the product via T3, IIOP, with a CVSS score of 9.8. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0, and successful exploitation can result in takeover of Oracle WebCenter Enterprise Capture. Evidence is limited to public sources and may not reflect the full scop [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-60916

The CVE-2026-60916 vulnerability is in the Client Bundle component of Oracle WebCenter Enterprise Capture, a product within Oracle Fusion Middleware. This vulnerability class allows unauthenticated attackers with network access via HTTP to compromise the product, potentially leading to high impacts on confidentiality, integrity, and availability. Successful attacks can result in unauthorized creation, del [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60915

The CVE-2026-60915 vulnerability affects the Imperative Web Server component of Helidon product in Oracle Fusion Middleware. This vulnerability has a CVSS score of 7.4 and can be exploited by unauthenticated attackers with network access via HTTP, potentially leading to unauthorized creation, deletion, or modification of critical data. Users of Helidon version 4.5.0 should be aware of this vulnerability a [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60909

The CVE-2026-60909 vulnerability affects Oracle WebCenter Content, a component of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability is classified as easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise the system. The vulnerability has a CVSS score of 7.6, indicating high severity, and can lead to unauthorized access [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60903

A difficult-to-exploit vulnerability in Oracle WebCenter Content allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Content. The vulnerability has a CVSS 3.1 Base Score of 8.7, indicating high severity. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle WebCenter Content accessible data, as well [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60902

The CVE-2026-60902 vulnerability is a difficult-to-exploit issue in Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.63, allowing a low-privileged attacker with logon to the infrastructure to compromise PeopleSoft Enterprise PeopleTools, potentially leading to takeover. This HIGH severity vulnerability has a CVSS 3.1 Base Score of 7.0, indicating high severity, with impacts on Confidentiality, Int [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60883

The PeopleSoft Enterprise PeopleTools product, specifically component PeopleCode, contains a vulnerability (CVE-2026-60883) affecting versions 8.61-8.63. This vulnerability is easily exploitable by high privileged attackers with network access via HTTP, potentially leading to takeover of PeopleSoft Enterprise PeopleTools. The CVSS 3.1 Base Score is 7.2, indicating high impacts on confidentiality, integrit [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-60873

The PeopleSoft Enterprise PeopleTools product, specifically versions 8.61-8.63, contains a difficult-to-exploit vulnerability that allows high privileged attackers with logon access to compromise the system. This vulnerability, tracked as CVE-2026-60873, requires human interaction and may significantly impact additional products. The CVSS 3.1 Base Score is 7.2, indicating high severity. Administrators and [truncated]