PatchSiren

Oracle Corporation CVE debriefs · Page 26

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-61024

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:33.807Z and has not been modified since then. The vulnerability affects Oracle iRecruitment, a component of Oracle E-Business Suite, specifically versions 12.2.3-12.2.15. It is a high-severity vulnerability with a CVSS score of 8.1, allowing low-privileged attackers with network access via [truncated]

LOW Oracle Corporation CVE published 2026-07-21

CVE-2026-61015

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:33.353Z and has not been modified since then. This vulnerability affects Oracle E-Business Suite, specifically the Time and Labor component, with versions 12.2.3-12.2.15 being vulnerable. The vulnerability is difficult to exploit and allows unauthenticated attackers with network access via [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-61013

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:33.130Z and has not been modified since then. The CVE-2026-61013 vulnerability is a difficult to exploit issue in Oracle Time and Labor, allowing high privileged attackers with network access via HTTP to compromise the system, potentially impacting additional products. Successful attacks ca [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60989

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:32.017Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. CVE-2026-60989 is a vulnerability in Oracle Advanced Collections, allowing low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in takeover [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60979

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:31.217Z and has not been modified since then. This high-severity vulnerability affects Oracle Scripting product versions 12.2.3-12.2.15, allowing unauthenticated network attackers to potentially takeover the product. Evidence is limited to CVE and NVD details. Defenders should verify affect [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60974

The CVE-2026-60974 vulnerability is a critical security issue in the Oracle E-Business Tax product of Oracle E-Business Suite, specifically in the Internal Operations component. This vulnerability affects supported versions 12.2.3-12.2.15 and allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modifica [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60973

The CVE-2026-60973 vulnerability is in the Oracle E-Business Tax product of Oracle E-Business Suite, specifically in the Internal Operations component. Supported versions that are affected are 12.2.3-12.2.15. The vulnerability is easily exploitable, allowing a low-privileged attacker with logon access to the infrastructure where Oracle E-Business Tax executes to compromise Oracle E-Business Tax. Successfu [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60972

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:30.777Z and has not been modified since then. The CVE-2026-60972 vulnerability affects Oracle E-Business Tax versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data creation, deletion, or modi [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60966

CVE-2026-60966 is a vulnerability in Oracle Public Sector Human Resources, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 8.1 and can be exploited by low-privileged attackers with network access via HTTP, potentially resulting in unauthorized access to critical data or complete access to all Oracle Public Sector Human Resources accessible data. Organizations should review th [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60962

The CVE-2026-60962 vulnerability affects Oracle Flow Manufacturing, a component of Oracle E-Business Suite. This vulnerability has a CVSS score of 5.4, indicating medium severity. It allows low-privileged attackers with network access via HTTP to compromise the product, requiring human interaction. Successful attacks can lead to unauthorized update, insert, or delete access to some accessible data and una [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60960

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:30.223Z and has not been modified since then. The vulnerability in Oracle SDP Number Portability, a component of Oracle E-Business Suite, allows low-privileged attackers with logon to the infrastructure to compromise the product. Successful attacks can result in takeover of Oracle SDP Numbe [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60959

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:30.117Z and has not been modified since then. The CVE-2026-60959 vulnerability affects Oracle SDP Number Portability, a component of Oracle E-Business Suite. It is classified as Easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the product. The [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60957

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:29.997Z and has not been modified since then. CVE-2026-60957 is a vulnerability in Oracle Transportation Execution, part of Oracle E-Business Suite. It has a CVSS 3.1 Base Score of 5.4 and can be exploited by low-privileged attackers with network access via HTTP. Successful attacks require [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60952

CVE-2026-60952 is a vulnerability in Oracle E-Business Suite's Oracle Transportation Execution component, allowing low-privileged attackers with network access via HTTP to compromise Oracle Transportation Execution, potentially leading to takeover. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS 3.1 score of 8.8, indicating HIGH severity. Oracle E-Business Suite administrators, security t [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60951

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:29.600Z and has not been modified since then. The vulnerability affects Oracle Time and Labor versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system. Organizations should verify their deployments and apply patches or mitigations as n [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60941

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:28.900Z and has not been modified since then. The CVE-2026-60941 vulnerability is an easily exploitable issue in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). It allows high privileged attackers with network access via HTTP to com [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60940

The CVE-2026-60940 vulnerability affects Oracle Service Contracts, a component of Oracle E-Business Suite. This difficult-to-exploit vulnerability allows high-privileged attackers with network access via HTTP to compromise Oracle Service Contracts. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized creation, deletion, or modification access to [truncated]

LOW Oracle Corporation CVE published 2026-07-21

CVE-2026-60937

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:28.440Z and has not been modified since then. CVE-2026-60937 is a vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite, affecting versions 12.2.3-12.2.15. This difficult-to-exploit vulnerability allows low-privileged attackers with network access via HTTP to com [truncated]

LOW Oracle Corporation CVE published 2026-07-21

CVE-2026-60936

The CVE-2026-60936 vulnerability is in the Internal Operations component of Oracle Labor Distribution in Oracle E-Business Suite versions 12.2.3-12.2.15. This is a difficult-to-exploit vulnerability that allows a low-privileged attacker with network access via HTTP to compromise Oracle Labor Distribution, potentially causing a partial denial of service. Oracle E-Business Suite users, specifically those us [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60927

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:27.783Z and has not been modified since then. The CVE-2026-60927 vulnerability is a difficult-to-exploit issue in Oracle Public Sector Financials, allowing low privileged attackers with network access via HTTP to compromise the product, potentially leading to takeover. Organizations should [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60926

The CVE-2026-60926 vulnerability affects Oracle Public Sector Payroll, a component of Oracle E-Business Suite. This vulnerability class allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The affected versions are 12.2.3-12.2.15. Organizations should review their deployments and prioritize patching to prevent potential security breaches. [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60925

The CVE-2026-60925 vulnerability is a high-severity issue in the Internal Operations component of Oracle Public Sector Payroll, part of Oracle E-Business Suite. It allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The vulnerability has a CVSS 3.1 Base Score of 7.2, indicating high severity. Affected versions are 12.2.4 through 12.2.15. [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60924

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:27.470Z and has not been modified since then. The CVE-2026-60924 vulnerability affects Oracle Public Sector Payroll versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in takeover of Oracle Public Se [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60923

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:27.360Z and has not been modified since then. CVE-2026-60923 is a vulnerability in the Oracle Capacity product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacke [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60920

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:27.140Z and has not been modified since then. CVE-2026-60920 is a vulnerability in Oracle Customer Care, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 8.8, indicating high severity. It allows low-privileged attackers with network access via HTTP to compromise [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60918

The CVE-2026-60918 vulnerability affects Oracle Shipping Execution versions 12.2.12-12.2.15. It is classified as HIGH with a CVSS score of 7.2. High privileged attackers with network access via HTTP can compromise Oracle Shipping Execution, potentially leading to takeover. The CVE record was published on 2026-07-21T22:18:26.923Z and has not been modified since then. The NVD entry is currently Analyzed. Or [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60901

The CVE-2026-60901 vulnerability affects Oracle Project Intelligence, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in the takeover of Oracle Project Intelligence. The CVE record was published on 2026-07-21T22:18:25.910Z and has not been m [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60900

The CVE-2026-60900 vulnerability affects Oracle HCM Configuration Workbench, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing high privileged attackers with network access via HTTP to compromise the system. The potential impact is significant, as successful attacks can result in the takeover of Oracle HCM Configuration Workbench. The CVE record was p [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60899

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:25.683Z and has not been modified since then. The vulnerability in Oracle HCM Configuration Workbench allows a low privileged attacker with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data. Organizations using Oracle HCM Configura [truncated]

LOW Oracle Corporation CVE published 2026-07-21

CVE-2026-60896

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:25.350Z and has not been modified since then. The vulnerability affects Oracle Work in Process versions 12.2.3-12.2.15, and is difficult to exploit for low privileged attackers. It allows unauthorized read access and partial denial of service. The CVSS 3.1 Base Score is 3.6 (Confidentiality [truncated]