PatchSiren

Oracle Corporation CVE debriefs · Page 21

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-62444

A vulnerability exists in Oracle Contracts Integration, a component of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP, potentially leading to unauthorized data access and modifications. Successful attacks require human interaction and can result in unauthorized update, insert, or delete [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-62443

A vulnerability was found in Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). The affected versions are 12.2.3-12.2.15. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker and can result in unauthorize [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61338

A vulnerability was found in Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). The supported versions that are affected are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks can result in unauthorized creation, deletion, or modification access to cri [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61337

A high-severity vulnerability was discovered in Oracle Lease and Finance Management, a product of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61337, has a CVSS score of 7.5 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of the affected system. This vulnerability is located in the Internal Operations component and is dif [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61336

A high-severity vulnerability was discovered in Oracle Lease and Finance Management, affecting versions 12.2.14-12.2.15. This easily exploitable vulnerability allows high-privileged attackers with network access via HTTP to compromise the system, potentially leading to a takeover. The vulnerability has a CVSS 3.1 score of 7.2, indicating high confidentiality, integrity, and availability impacts. Organizat [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61335

A high-severity vulnerability was discovered in Oracle Product Workbench, affecting versions 12.2.3-12.2.15. This easily exploitable vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability has a CVSS 3.1 Base Score of 8.1, indicating a high impact on conf [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61334

A vulnerability exists in Oracle Price Protection, a component of Oracle E-Business Suite. The affected versions are 12.2.3 through 12.2.15. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized creation, deletion, or modification of critical data or all Oracle Price Protection accessible data, as well as unauthorized read a [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61333

A high-severity vulnerability was discovered in Oracle Product Workbench, affecting versions 12.2.3-12.2.15. This easily exploitable vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability has a CVSS 3.1 Base Score of 8.1, indicating high confidentiality [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61329

A vulnerability exists in Oracle Price Protection, a component of Oracle E-Business Suite. The affected versions are 12.2.3 through 12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data or all Oracle Price Protection accessible data, as [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61328

A vulnerability was discovered in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. This difficult-to-exploit vulnerability allows a high-privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in the takeover of Oracle Cost Man [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61327

A high-severity vulnerability was discovered in Oracle Bills of Material, a product of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61327, has a CVSS score of 8.1 and allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to c [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61325

A high-severity vulnerability was found in Oracle Advanced Benefits, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61325, has a CVSS score of 7.6 and can be easily exploited by high-privileged attackers with network access via HTTP. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Advanced Benefits accessible data, as w [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61324

A vulnerability exists in Oracle Advanced Benefits, a component of Oracle E-Business Suite. The affected version is 12.2.15. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially compromising Oracle Advanced Benefits and impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification of critical data [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61323

A vulnerability was discovered in Oracle Advanced Benefits, a component of Oracle E-Business Suite. The vulnerability has been identified as CVE-2026-61323 and has a CVSS score of 6.5, classified as MEDIUM. The affected version is 12.2.15. An attacker with low privileges and network access via HTTP can exploit this vulnerability to compromise Oracle Advanced Benefits, potentially leading to unauthorized a [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61322

A vulnerability was discovered in the TeleSales product of Oracle E-Business Suite (component: Internal Operations). The supported versions affected are 12.2.3-12.2.15. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise TeleSales. Successful attacks can result in the takeover of TeleSales. The CVSS 3.1 Base Score is 8.8, indicating a hi [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61320

A vulnerability was discovered in Oracle Payables, a component of Oracle E-Business Suite. The vulnerability affects versions 12.2.8-12.2.15 and has a CVSS score of 8.8, indicating high severity. An attacker with low privileges and network access via HTTP can exploit this vulnerability to compromise Oracle Payables, potentially leading to takeover. The vulnerability is located in the Internal Operations c [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61316

A medium-severity vulnerability was found in Oracle EDI Gateway, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61316, has a CVSS score of 4.3 and allows a low-privileged attacker with network access via HTTP to compromise Oracle EDI Gateway, potentially leading to unauthorized read access to a subset of Oracle EDI Gateway accessible data. The vulnerability is located in th [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61315

A vulnerability exists in Oracle EDI Gateway, a component of Oracle E-Business Suite. The affected versions are 12.2.3 through 12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle EDI Gateway, potentially leading to unauthorized read access to a subset of accessible data. Organizations should prioritize patching this vulnerability to prevent potent [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61314

A high-severity vulnerability was discovered in Oracle EDI Gateway, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61314, has a CVSS score of 7.2 and allows high-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in a takeover of Oracle EDI Gateway. This vulnerability is located in the 'All Miscellaneous EDI Issues' com [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61312

A high-severity vulnerability was found in Oracle Product Hub, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61312, has a CVSS score of 8.5 and can be exploited by low-privileged attackers with network access via HTTP. Successful attacks can result in the takeover of Oracle Product Hub and potentially impact additional products. The vulnerability is difficult to exploit bu [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61311

A high-severity vulnerability was found in Oracle Product Hub, affecting versions 12.2.3-12.2.15. This easily exploitable vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle Product Hub, potentially leading to a full takeover. The vulnerability is located in the Internal Operations component and has a CVSS 3.1 Base Score of 8.8, indicating high impacts on Confid [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61310

A vulnerability exists in Oracle Product Hub, a component of Oracle E-Business Suite. The affected versions are 12.2.3 through 12.2.15. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Product Hub [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61309

A vulnerability was discovered in Oracle In-Memory Cost Management for Discrete Industries, a component of Oracle E-Business Suite. The vulnerability is rated as HIGH with a CVSS 3.1 Base Score of 7.5, impacting confidentiality. It allows an unauthenticated attacker with network access via HTTP to compromise Oracle In-Memory Cost Management for Discrete Industries, potentially leading to unauthorized acce [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61304

A vulnerability was discovered in Oracle Price Protection, a component of Oracle E-Business Suite. The affected versions are 12.2.3 through 12.2.15. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data, unauthori [truncated]

LOW Oracle Corporation CVE published 2026-07-21

CVE-2026-61303

A low-severity vulnerability was found in Oracle EDI Gateway, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 1.9 and allows high privileged attackers with logon access to the infrastructure to compromise Oracle EDI Gateway, potentially leading to unauthorized read access to a subset of Oracle EDI Gateway accessible data. The vulnerability is located in the Internal Operation [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61301

A high-severity vulnerability was discovered in Oracle Process Manufacturing Financials, a product of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61301, affects versions 12.2.3-12.2.15 and allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or al [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61299

A vulnerability was discovered in Oracle Process Manufacturing Logistics, a product of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS 3.1 Base Score of 7.1, indicating high severity. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics, potentially leading to unauthorized access to cr [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61297

A vulnerability exists in Oracle Customers Online, a component of Oracle E-Business Suite. The affected versions are 12.2.3 through 12.2.15. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized creation, deletion, or modification of critical data or all Oracle Customers Online accessible data, as well as unauthorized access [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61294

A vulnerability was discovered in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). The affected versions are 12.2.3-12.2.15. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks can result in unauthorized update, insert or de [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61289

A high-severity vulnerability was found in Oracle Process Manufacturing Product Development, specifically in the Quality Management Specs component, version 12.2.15. The vulnerability has a CVSS score of 8.8 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of the product. This vulnerability impacts Confidentiality, Integrity, and Availabilit [truncated]