PatchSiren

Oracle Corporation CVE debriefs · Page 20

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62507

A vulnerability was discovered in Oracle Time and Labor, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 5.3 and can allow a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability is located in the Internal Operations component and has a CVSS Vec [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62505

A vulnerability was discovered in Oracle Time and Labor, a component of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS score of 6.1. It allows unauthenticated attackers with network access via HTTP to compromise Oracle Time and Labor, potentially impacting additional products. Successful attacks require human interaction and can result in unauthorized access to s [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62504

A high-severity vulnerability was discovered in Oracle Time and Labor, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62504, has a CVSS score of 8.1 and allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to cr [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62503

A high-severity vulnerability was discovered in Oracle Time and Labor, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62503, allows high privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete acc [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62496

A high-severity vulnerability was found in Oracle Yard Management, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62496, has a CVSS score of 8.8 and can be easily exploited by low-privileged attackers with network access via HTTP, potentially leading to a takeover of the Oracle Yard Management system. This vulnerability affects versions 12.2.6-12.2.15 of Oracle Yard Managem [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62495

A high-severity vulnerability was found in Oracle Process Manufacturing Process Execution with a CVSS score of 7.5. The vulnerability has been publicly disclosed and is considered difficult to exploit. It is located in the Internal Operations component and requires low privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in takeover of Oracle Process Ma [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62494

A high-severity vulnerability, CVE-2026-62494, was discovered in Oracle Time and Labor, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 8.1 and allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62493

A high-severity vulnerability was identified in Oracle Purchasing, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62493, has a CVSS score of 7.5 and can be exploited by low-privileged attackers with network access via HTTP, potentially leading to a takeover of Oracle Purchasing. This vulnerability affects versions 12.2.11-12.2.15 and is considered difficult to exploit. Succ [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62489

A medium-severity vulnerability was found in Oracle Contracts Integration, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 4.2 and can allow a low-privileged attacker with network access via HTTP to compromise the system, leading to unauthorized update, insert, or delete access to some accessible data and unauthorized read access to a subset of accessible data. This vulnerabi [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62488

A vulnerability was found in Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). The supported versions that are affected are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks can result in unauthorized creation, deletion, or modification access to cri [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62487

A vulnerability exists in Oracle Contracts Integration, a component of Oracle E-Business Suite, specifically in versions 12.2.3-12.2.15. This vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP, potentially leading to unauthorized data access and modifications. Successful attacks require human interaction and can result in unauthorized update, insert, or delete [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62486

A medium-severity vulnerability was found in Oracle Contracts Integration, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62486, has a CVSS score of 5.0 and can allow an unauthenticated attacker with network access via HTTP to compromise the system. This vulnerability is difficult to exploit and requires human interaction from a person other than the attacker.

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62484

A medium-severity vulnerability was found in Oracle Contracts Integration, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62484, has a CVSS score of 5.9 and can allow an unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62483

A vulnerability was discovered in Oracle Project Contracts, a component of Oracle E-Business Suite. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data. The vulnerability affects versions 12.2.3-12.2.15 of Oracle Project Contr [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62480

A vulnerability was found in Oracle Public Sector Financials, a product within Oracle E-Business Suite. The vulnerability affects the Internal Operations component and has a CVSS score of 6.5, indicating a medium severity. It allows low-privileged attackers with network access via HTTP to compromise Oracle Public Sector Financials, potentially leading to unauthorized access to critical data. The vulnerabi [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62479

A vulnerability was found in Oracle Public Sector Financials, a product of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and has been rated with a CVSS score of 5.4, indicating a medium severity level. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks require human interaction from [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62478

A high-severity vulnerability exists in Oracle Public Sector Financials, an Oracle E-Business Suite product. The vulnerability has a CVSS 3.1 Base Score of 8.8, indicating high severity. It is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle Public Sector Financials. Organizations should prioritize patching to prevent potential takeovers.

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62476

A high-severity vulnerability was discovered in Oracle Public Sector Payroll, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62476, has a CVSS score of 8.8 and can be easily exploited by low-privileged attackers with network access via HTTP, potentially leading to a takeover of the affected system. This vulnerability affects versions 12.2.3-12.2.15 of Oracle Public Sector P [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62474

A vulnerability was discovered in Oracle Lease and Finance Management, a product of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and is exploitable by low-privileged attackers with network access via HTTP. Successful attacks can result in unauthorized update, insert or delete access to some accessible data, unauthorized read access to a subset of accessible data, and partial [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62473

A vulnerability exists in Oracle Installed Base, a component of Oracle E-Business Suite. The affected versions are 12.2.3 through 12.2.15. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data, unauthorized access to crit [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62472

A vulnerability exists in Oracle Installed Base, a component of Oracle E-Business Suite. The affected versions are 12.2.4 through 12.2.15. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Insta [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62470

A vulnerability was discovered in Oracle Self-Service Human Resources, a component of Oracle E-Business Suite. The vulnerability, CVE-2026-62470, has a CVSS score of 6.5 and is classified as medium severity. It allows a low-privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources, potentially leading to unauthorized access to critical data. The vulnerability is in [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62468

A high-severity vulnerability was discovered in Oracle Human Resources, specifically in the Enterprise Command Center component. The vulnerability, tracked as CVE-2026-62468, has a CVSS score of 8.1 and can be exploited by low-privileged attackers with network access via HTTP. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62465

A vulnerability was discovered in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). The affected versions are 12.2.9-12.2.15. This vulnerability allows a low-privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks can result in unauthorized ability to cause a hang or frequently repeatabl [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62464

A high-severity vulnerability was found in Oracle Payroll, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62464, has a CVSS score of 8.8 and can be easily exploited by low-privileged attackers with network access via HTTP, potentially leading to a takeover of Oracle Payroll. This vulnerability affects versions 12.2.3-12.2.15 of Oracle Payroll. The CVSS Vector is (CVSS:3.1/A [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62456

A high-severity vulnerability was discovered in Oracle HRMS (UK), a product of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62456, has a CVSS score of 8.2 and can be exploited by a low-privileged attacker with network access via HTTPS. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle HRMS (UK) accessible data, as wel [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62453

A vulnerability was discovered in Oracle HRMS (UK), a product of Oracle E-Business Suite, affecting versions 12.2.3-12.2.15. The vulnerability is exploitable by low-privileged attackers with network access via HTTP, potentially leading to unauthorized update, insert, or delete access to some accessible data, unauthorized read access to a subset of accessible data, and partial denial of service. The CVSS 3 [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62451

A high-severity vulnerability exists in Oracle Work in Process, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-62451, has a CVSS score of 8.1 and can be easily exploited by a low-privileged attacker with network access via HTTP. Successful attacks could result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62447

A high-severity vulnerability was found in Oracle Trade Management's Claim LOV component, affecting versions 12.2.3-12.2.15. The vulnerability has a CVSS score of 8.8, indicating high confidentiality, integrity, and availability impacts. It can be easily exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle Trade Management. Security teams and adm [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62445

A vulnerability exists in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). The affected versions are 12.2.4-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracl [truncated]