PatchSiren

Oracle Corporation CVE debriefs · Page 22

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61287

A high-severity vulnerability was found in Oracle Process Manufacturing Systems, a product of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61287, affects versions 12.2.3-12.2.15 and allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61285

A high-severity vulnerability was discovered in Oracle Process Manufacturing Systems, a product of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61285, affects versions 12.2.11-12.2.15 and allows high-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in a takeover of Oracle Process Manufacturing Systems. This vulnerability has a hig [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61283

A vulnerability was discovered in Oracle Bills of Material, a product of Oracle E-Business Suite. The vulnerability is related to the Web Services component and affects versions 12.2.3-12.2.15. A low-privileged attacker with network access via HTTP can exploit this vulnerability, potentially leading to unauthorized data access and partial denial of service. This vulnerability has a CVSS 3.1 Base Score of [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61282

A vulnerability was discovered in Oracle Advanced Benefits, a component of Oracle E-Business Suite. The vulnerability is rated as medium severity with a CVSS score of 6.3. It allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert or delete access to some accessible data, unauthorized read access to a subset of ac [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61280

A vulnerability was discovered in Oracle Sales for Handhelds, a product of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and is exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation can lead to unauthorized update, insert, or delete access to some accessible data, unauthorized read access to a subset of accessible data, and a partial de [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61279

A vulnerability was discovered in the Oracle Proposals product of Oracle E-Business Suite (component: Proposals). The affected versions are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Proposals. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle Proposals accessible data, unauthorized rea [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61278

A vulnerability was discovered in Oracle Workflow, a component of Oracle E-Business Suite. The vulnerability is rated with a CVSS 3.1 Base Score of 6.3, indicating a medium severity level. It allows low-privileged attackers with network access via HTTP to compromise Oracle Workflow, potentially leading to unauthorized data access and partial denial of service. The vulnerability is located in the Workflow [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61277

A vulnerability was discovered in Oracle Marketing, a component of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks can result in unauthorized update, insert, or delete access to some Oracle Marketing accessible data, unauthorized r [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61275

A vulnerability was discovered in Oracle Product Hub, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61275, is related to Role-Based Security and has a CVSS score of 6.3, indicating a medium severity level. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Product Hub, potentially leading to unauthorized data access and par [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61271

A vulnerability exists in Oracle Document Management and Collaboration, a component of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks can result in unauthorized update, insert or delete access to some accessible data, unauthor [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61269

A vulnerability exists in Oracle Product Workbench, a component of Oracle E-Business Suite. This vulnerability, listed as CVE-2026-61269, affects versions 12.2.3 through 12.2.15 and is exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation can lead to unauthorized update, insert, or delete access to some Oracle Product Workbench data, unauthorized read access to a s [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61267

A high-severity vulnerability was discovered in Oracle HCM Configuration Workbench, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-61267, has a CVSS score of 7.3 and can be exploited by unauthenticated attackers with network access via HTTP. Successful attacks can result in unauthorized update, insert or delete access to some accessible data, unauthorized read access to a s [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61266

A vulnerability was discovered in Oracle Supply Chain Globalization, a product of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and is exploitable by low-privileged attackers with network access via HTTP. Successful attacks can result in unauthorized update, insert or delete access to some accessible data, unauthorized read access to a subset of accessible data, and a partial [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61264

A vulnerability exists in Oracle Call Center Technology, a component of Oracle E-Business Suite. The affected versions are 12.2.3 through 12.2.15. This vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data, as we [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61263

A vulnerability was discovered in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). The affected versions are 12.2.3-12.2.15. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle Scripting accessib [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61262

A vulnerability was discovered in Oracle Teleservice, a component of Oracle E-Business Suite. The vulnerability is rated as MEDIUM with a CVSS score of 6.5. It allows an unauthenticated attacker with network access via HTTP to compromise Oracle Teleservice, potentially leading to unauthorized update, insert or delete access to some of Oracle Teleservice accessible data as well as unauthorized read access [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61261

A vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: User Interface) allows low-privileged attackers with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data as well as unauthorized read access to a subset of Oracle [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61260

A vulnerability was discovered in Oracle HRMS (UK), a product of Oracle E-Business Suite, specifically in the UK Payroll component. The affected versions are 12.2.3-12.2.15. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized update, insert, or delete access to some Oracle HRMS (UK) accessible data, as well as unauthorized [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61257

A vulnerability was discovered in the Oracle iSupport product of Oracle E-Business Suite (component: Call Back). The affected versions are 12.2.3-12.2.15. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle iSupport accessible data a [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61255

A medium severity vulnerability was found in Oracle HRMS (New Zealand), affecting versions 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle HRMS (New Zealand), potentially leading to unauthorized update, insert, or delete access to some accessible data and unauthorized read access to a subset of accessible data. The vulnerability has a C [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61254

A vulnerability was discovered in Oracle HRMS (Republic of Korea), a component of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS score of 5.4, indicating a medium severity level. An unauthenticated attacker with network access via HTTP can exploit this vulnerability, which requires human interaction from another person. Successful attacks can lead to unauthorized [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61253

A vulnerability was found in Oracle HRMS (Japanese) of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability allows an unauthenticated attacker with network access via HTTPS to compromise Oracle HRMS (Japanese). Successful attacks require human interaction. The impact includes unauthorized update, insert or delete access to some accessible data and unauthorized read access [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61252

A vulnerability was discovered in Oracle HRMS (Hong Kong) affecting versions 12.2.13-12.2.15. This easily exploitable vulnerability allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data and unauthorized read access to a subset of accessible data. The vulnerability has a m [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61251

A vulnerability was discovered in the HRMS (Australia) product of Oracle E-Business Suite, specifically in the Payroll component. The affected versions are 12.2.3-12.2.15. This medium-severity issue has a CVSS 3.1 Base Score of 6.5, primarily impacting confidentiality. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise HRMS (Australia), potentially leading to una [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61250

A vulnerability was discovered in Oracle Payroll, a component of Oracle E-Business Suite. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. The vulnerability has a CVSS 3.1 Base Score of 6.5, ind [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61249

A vulnerability was discovered in Oracle Learning Management, a product of Oracle E-Business Suite, specifically in the Import And Export component. The vulnerability affects versions 12.2.3-12.2.15 and allows a low-privileged attacker with network access via HTTP to compromise Oracle Learning Management, potentially leading to unauthorized access to critical data. The vulnerability has a medium severity [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61247

A vulnerability was discovered in Oracle Workflow, a component of Oracle E-Business Suite. The issue affects versions 12.2.3 through 12.2.15. It is a difficult-to-exploit vulnerability that allows an unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks can result in unauthorized update, insert, or delete access to some Oracle Workflow accessible data and [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-61245

A critical vulnerability was identified in PeopleSoft Enterprise FIN Manufacturing Brazil, allowing unauthenticated attackers to compromise the system via HTTPS. The vulnerability has a CVSS score of 9.8 and can result in a complete takeover of the affected system. This vulnerability affects the Integration component of PeopleSoft Enterprise FIN Manufacturing Brazil, version 9.1. The CVSS 3.1 Base Score i [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-61244

A critical vulnerability was discovered in PeopleSoft Enterprise FIN Manufacturing Argentina, a product of Oracle PeopleSoft. The vulnerability has a CVSS score of 9.1 and can allow unauthenticated attackers to compromise the system via HTTP. This could lead to unauthorized creation, deletion, or modification of critical data. Organizations should prioritize patching to prevent potential attacks.

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61243

A vulnerability was discovered in PeopleSoft Enterprise FIN Common Objects Argentina, a product of Oracle PeopleSoft. The vulnerability is rated as HIGH with a CVSS score of 8.8. It is located in the Staffing component of PeopleSoft Enterprise FIN Common Objects Argentina, version 9.1. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise the system, potentially lea [truncated]