These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-60412 vulnerability affects Oracle Outside In Technology version 8.5.8, allowing an unauthenticated attacker with logon to the infrastructure to compromise the system. Successful attacks require human interaction and can result in takeover of Oracle Outside In Technology. This vulnerability has a high CVSS score of 7.8, indicating significant confidentiality, integrity, and availability impac [truncated]
The CVE-2026-60392 vulnerability affects Oracle Outside In Technology, specifically the Outside In PDF Export SDK component, version 8.5.8. This vulnerability is easily exploitable by an unauthenticated attacker with logon to the infrastructure, requiring human interaction. Successful attacks can lead to takeover of Oracle Outside In Technology. The CVSS 3.1 score is 7.8, indicating high severity. Adminis [truncated]
The CVE-2026-60391 vulnerability affects Oracle Hyperion Financial Reporting product, specifically the Server component, version 11.2.25.0.000. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting, potentially leading to unauthorized access to critical data. The CVSS 3.1 Base Score is 7.5, with Confidentiality impacts. Organiz [truncated]
A high-severity vulnerability was found in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. This vulnerability, located in the Install component, allows a low-privileged attacker with logon to the infrastructure to compromise the products. Successful attacks can result in takeover of the affected products. The CVSS 3.1 Base Score is 7.8, indicating high confidentiality, integ [truncated]
A vulnerability was discovered in the Oracle HRMS (US) product of Oracle E-Business Suite, specifically in the US Payroll Year End component. The affected versions are 12.2.3-12.2.15. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data, as w [truncated]
A vulnerability was discovered in Oracle Work in Process, a component of Oracle E-Business Suite. The vulnerability is easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction and can result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read acces [truncated]
A vulnerability was discovered in Oracle HRMS (US), an Oracle E-Business Suite component. The vulnerability, tracked as CVE-2026-62562, has a CVSS 3.1 Base Score of 6.5, indicating a medium severity level. It affects versions 12.2.3-12.2.15 and allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data. The vulnerabili [truncated]
A high-severity vulnerability was found in Oracle HRMS (US), a product of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS score of 7.8. It is located in the Internal Operations component and allows a low-privileged attacker with logon access to compromise the system. Successful attacks can result in takeover of Oracle HRMS (US). The CVSS vector is CVSS:3.1/AV:L/AC [truncated]
A high-severity vulnerability was discovered in Oracle HRMS (Norway), a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62560, has a CVSS score of 7.7 and can be exploited by low-privileged attackers with network access via HTTP. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle HRMS (Norway) accessible data. This vulnerabil [truncated]
A vulnerability was discovered in Oracle HRMS (US), a product of Oracle E-Business Suite, specifically in the Internal Operations component. The affected versions are 12.2.3-12.2.15. This vulnerability is easily exploitable by a high privileged attacker with network access via HTTP, potentially compromising Oracle HRMS (US) and impacting additional products due to scope change. Successful attacks can resu [truncated]
A vulnerability was discovered in Oracle HRMS (UK), a product of Oracle E-Business Suite, specifically in the UK Payroll component. The affected versions are 12.2.3-12.2.15. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data, as well as una [truncated]
A vulnerability was discovered in Oracle HRMS (US), an Oracle E-Business Suite component. The vulnerability, CVE-2026-62556, has a CVSS score of 6.5 and is considered medium severity. It affects versions 12.2.6-12.2.15 and allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data. The vulnerability is located in the I [truncated]
A critical vulnerability was discovered in Oracle HRMS (UK), a product of Oracle E-Business Suite, specifically in the UK Payroll component. The vulnerability affects versions 12.2.3-12.2.15 and has been assigned a CVSS 3.1 Base Score of 9.6, indicating high confidentiality and integrity impacts. An attacker with low privileges and network access via HTTP can easily exploit this vulnerability to compromis [truncated]
A high-severity vulnerability was discovered in Oracle HRMS (US), a product of Oracle E-Business Suite, affecting versions 12.2.3-12.2.15. The vulnerability, located in the Internal Operations component, has been assigned a CVSS 3.1 Base Score of 7.2, indicating high confidentiality, integrity, and availability impacts. This easily exploitable vulnerability allows high-privileged attackers with network ac [truncated]
A high-severity vulnerability was found in Oracle Workflow, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 8.1 and can be exploited by unauthenticated attackers with network access via SMTP, potentially leading to a takeover of Oracle Workflow. This vulnerability is located in the Workflow Notification Mailer component and affects versions 12.2.3-12.2.15. The exploitation of [truncated]
A critical vulnerability was identified in the Oracle Applications Framework product of Oracle E-Business Suite, specifically in the Web Utilities component. The vulnerability is easily exploitable and allows high privileged attackers with network access via HTTP to compromise Oracle Applications Framework. Successful attacks can result in takeover of Oracle Applications Framework, potentially impacting a [truncated]
A vulnerability was found in Oracle Advanced Benefits, a component of Oracle E-Business Suite. The vulnerability is rated as medium with a CVSS score of 6.3. A low-privileged attacker with network access via HTTP can exploit this vulnerability to compromise Oracle Advanced Benefits, leading to unauthorized update, insert or delete access to some accessible data, unauthorized read access to a subset of acc [truncated]
The CVE-2026-62534 vulnerability affects Oracle Applications Framework, a component of Oracle E-Business Suite. Supported versions 12.2.11-12.2.15 are impacted. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Applications Framework, potentially leading to a takeover. The CVSS 3.1 Base Score is 8.8, indicating high severity. Organizat [truncated]
A high-severity vulnerability was found in Oracle HRMS (France), a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62530, has a CVSS score of 8.1 and can be easily exploited by low-privileged attackers with network access via HTTP. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data [truncated]
A vulnerability was discovered in Oracle HCM Configuration Workbench, a component of Oracle E-Business Suite. The vulnerability has been assigned a CVSS 3.1 Base Score of 6.3, indicating a medium severity level. The vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks can result in unautho [truncated]
A vulnerability was discovered in Oracle Learning Management, a product of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and is categorized under the component Import And Export. It allows a low-privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks can result in unauthorized update, insert or delete access to some accessi [truncated]
A vulnerability exists in Oracle Quality, a component of Oracle E-Business Suite. The affected versions are 12.2.3 through 12.2.15. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks can result in unauthorized update, insert, or delete access to some Oracle Quality accessible data, unauthorized read ac [truncated]
A high-severity vulnerability was found in Oracle HRMS (US), specifically in the US Payroll - General component. The vulnerability has a CVSS score of 7.5 and can be easily exploited by unauthenticated attackers with network access via HTTP, potentially leading to unauthorized access to critical data. This vulnerability affects Oracle HRMS (US) versions 12.2.7-12.2.15 and has a high CVSS score indicating [truncated]
A vulnerability exists in Oracle Succession planning, a component of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Succession planning. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle Succession planning accessible data, unauthorized rea [truncated]
A vulnerability was found in Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). The supported versions that are affected are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks can result in unauthorized creation, deletion, or modification access to cri [truncated]
A vulnerability exists in Oracle Production Scheduling, a component of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This difficult-to-exploit vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized access t [truncated]
A vulnerability was discovered in Oracle Demantra Demand Management, a product of Oracle Supply Chain, specifically in the Product Security component. The affected versions are 12.2.3-12.2.15. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via SQL to compromise Oracle Demantra Demand Management. Successful attacks can result in the takeover of Oracle Dema [truncated]
A high-severity vulnerability was discovered in Oracle Advanced Planning Command Center, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62515, has a CVSS score of 7.6 and allows high privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Advanced Plann [truncated]
A high-severity vulnerability was found in Oracle Process Manufacturing Regulatory Management, part of Oracle E-Business Suite. The issue, tracked as CVE-2026-62513, has a CVSS 3.1 score of 8.5, indicating high confidentiality and integrity impacts. The vulnerability affects versions 12.2.3-12.2.15 and can be exploited by low-privileged attackers with network access via HTTP. Successful attacks could lead [truncated]
A low-severity vulnerability was found in Oracle Time and Labor, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62508, has a CVSS score of 3.1 and can allow a low-privileged attacker with network access via HTTP to cause a partial denial of service. The vulnerability is located in the Internal Operations component of Oracle Time and Labor, affecting versions 12.2.3-12.2.15. [truncated]