PatchSiren

Oracle Corporation CVE debriefs · Page 28

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60794

The CVE-2026-60794 vulnerability affects Oracle TeleSales, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the system. The potential impact includes unauthorized update, insert, or delete access to some of Oracle TeleSales accessible data, as well as unauthorized read access to a su [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60793

The CVE-2026-60793 vulnerability affects Oracle TeleSales, a product of Oracle E-Business Suite. The vulnerability is located in the Internal Operations component and has a CVSS score of 8.1, indicating high severity. The vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, leading to unauthorized creation, deletion, or modification of critical data. Organiz [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60785

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:17.500Z and has not been modified since then. This vulnerability affects Oracle iReceivables, a component of Oracle E-Business Suite, specifically versions 12.2.3-12.2.15. It is a difficult-to-exploit vulnerability that allows unauthenticated attackers with network access via HTTP to compro [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60784

The CVE-2026-60784 vulnerability affects Oracle Trading Community, a component of Oracle E-Business Suite, specifically in the Party Search UI. This vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the system. The potential impact includes unauthorized creation, deletion, or modification access to critical data or all Oracle Tr [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60783

The CVE-2026-60783 vulnerability affects Oracle iReceivables, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise Oracle iReceivables, potentially leading to a takeover of the system. The vulnerability impacts versions 12.2.3-12.2.15 of Oracle iReceivables. The CVSS 3.1 Base Score is 8. [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60773

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:16.443Z and has not been modified since then. The CVE-2026-60773 vulnerability in Oracle Application Object Library has a CVSS 3.1 Base Score of 9.6, indicating critical severity. It allows low-privileged attackers with network access via HTTPS to compromise the library, potentially impacti [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60772

The CVE-2026-60772 vulnerability affects Oracle E-Business Suite versions 12.2.3-12.2.15, specifically the Oracle Financials Common Modules component. This vulnerability is easily exploitable by low-privileged attackers with network access via HTTP, potentially leading to unauthorized data access and modification. The CVSS 3.1 Base Score is 7.1, indicating high severity. Organizations should review and ap [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60771

The CVE-2026-60771 vulnerability affects Oracle Complex Maintenance, Repair and Overhaul, a component of Oracle E-Business Suite. This vulnerability has a CVSS score of 8.1 and can be exploited by low-privileged attackers with network access via HTTP. The potential impact includes unauthorized data access and modification. Organizations should review and apply Oracle's security patches for CVE-2026-60771 [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60761

CVE-2026-60761 is a vulnerability in Oracle Applications DBA, affecting versions 12.2.3-12.2.15. This vulnerability has a CVSS score of 6.5 and allows low-privileged attackers with logon access to compromise Oracle Applications DBA, potentially impacting additional products. The vulnerability is easily exploitable and can result in unauthorized access to critical data or complete access to all Oracle Appl [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60756

The CVE-2026-60756 vulnerability affects Oracle EDI Gateway, a component of Oracle E-Business Suite versions 12.2.3-12.2.15. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle EDI Gateway, potentially leading to takeover. The CVSS 3.1 Base Score is 8.1, indicating high severity. Organizations should review and apply Oracle's security [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60744

The CVE-2026-60744 vulnerability is a difficult-to-exploit issue in Oracle Cost Management, affecting versions 12.2.3-12.2.15. It allows low privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data or complete access to all Oracle Cost Management accessible data. The CVSS 3.1 Base Score is 6.8, indi [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60740

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:14.460Z and has not been modified since then. The vulnerability affects Oracle E-Business Suite versions 12.2.3-12.2.15, specifically the Oracle Cash Management product. It is an easily exploitable vulnerability that allows low-privileged attackers with network access via HTTP to compromise [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60725

A vulnerability in MySQL Router allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. This vulnerability affects MySQL Router versions 8.4.0-8.4.10 and 9.7.0-9.7.1. The CVSS score of 7.4 indicates high severity, with significant impacts on confidentiality and integrity. To mitigate t [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60719

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:12.250Z and has not been modified since then. The vulnerability affects Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0, with a CVSS score of 9.9, indicating critical severity. This critical vulnerability in Oracle BI Publisher's Web Service API allows low-privileged att [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60718

CVE-2026-60718 is a vulnerability in the MySQL Server and MySQL Cluster products of Oracle MySQL, specifically in the Server: JSON component. The affected versions are MySQL Server: 9.7.0-9.7.1 and MySQL Cluster: 9.7.0-9.7.1. This vulnerability is easily exploitable by a low-privileged attacker with network access via multiple protocols, potentially leading to unauthorized ability to cause a hang or frequ [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60717

The CVE-2026-60717 vulnerability affects Oracle Complex Maintenance, Repair and Overhaul product versions 12.2.3-12.2.15. This vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the product. The likely operational impact includes unauthorized update, insert or delete access to some accessible data as well as unauthorized read acc [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60713

CVE-2026-60713 is a vulnerability in Siebel CRM Cloud Applications' Siebel Cloud Manager component, affecting versions 22.3-26.5. It allows low-privileged attackers with logon access to compromise the system, leading to unauthorized data updates, inserts, deletes, and reads. The CVSS 3.1 score is 4.4, indicating medium severity. Organizations should prioritize patching, focusing on systems with low-privil [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60712

A vulnerability was discovered in Siebel CRM Cloud Applications, specifically in the Siebel Cloud Manager component. The vulnerability allows a low-privileged attacker with logon access to the infrastructure where Siebel CRM Cloud Applications executes to compromise the application. Successful attacks can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Application [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60711

A critical vulnerability was discovered in Siebel CRM Cloud Applications, a product of Oracle Siebel CRM. The vulnerability affects versions 22.3-26.5 and is classified under the component Siebel Cloud Manager. This vulnerability has a CVSS 3.1 Base Score of 9.9, indicating a critical severity level. It is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise S [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60710

CVE-2026-60710 is a vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). The vulnerability affects versions 12.2.3-12.2.15 and allows low-privileged attackers with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle EDI Gatewa [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60709

The CVE-2026-60709 vulnerability affects Siebel CRM Cloud Applications versions 22.3-26.5, a difficult-to-exploit vulnerability that allows unauthenticated attackers with access to the physical communication segment to compromise the application. This could result in unauthorized update, insert, or delete access to some accessible data and unauthorized read access to a subset of accessible data. The CVSS [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60708

The CVE-2026-60708 vulnerability affects Oracle E-Business Suite versions 12.2.3-12.2.15, specifically the Oracle Process Manufacturing Financials component. This vulnerability is easily exploitable by low-privileged attackers with network access via HTTP, potentially leading to unauthorized data access and modification. The CVSS 3.1 Base Score is 8.1, indicating high severity. Organizations should priori [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60697

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:10.373Z and has not been modified since then. The CVE-2026-60697 vulnerability is a medium-severity issue affecting Oracle E-Business Suite versions 12.2.3-12.2.15. It resides in the Site Hierarchy Flows component of Oracle Site Hub and allows low-privileged attackers with network access vi [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60687

The CVE-2026-60687 vulnerability affects Oracle E-Business Suite versions 12.2.3-12.2.15, specifically within the Oracle U.S. Federal Financials component. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via HTTPS to compromise Oracle U.S. Federal Financials, potentially impacting additional products. Successful attacks can result in unauthorized access to crit [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60686

CVE-2026-60686 is a vulnerability in Oracle E-Business Suite, specifically in the U.S. Federal Financials product. This vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle U.S. Federal Financials, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability has a CVSS score of 8.1 and can lead to unauthorized access [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60685

The CVE-2026-60685 vulnerability affects Oracle E-Business Suite's iSupport product, versions 12.2.3-12.2.15. It is a highly exploitable vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle iSupport, potentially impacting additional products. Successful attacks require human interaction and have a CVSS score of 6.1 with MEDIUM severity. Organizations should [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60681

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:08.910Z and has not been modified since then. CVE-2026-60681 is a high-severity vulnerability in Oracle Process Manufacturing Regulatory Management, a component of Oracle E-Business Suite. It has a CVSS 3.1 Base Score of 8.8 and is easily exploitable by low-privileged attackers with network [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60677

The CVE-2026-60677 vulnerability is a difficult-to-exploit issue in Oracle Common Application Components of Oracle E-Business Suite (component: Oracle Common Modules) versions 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Common Application Components, potentially impacting additional products. Successful attacks can result in unautho [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60675

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:08.453Z and has not been modified since then. The CVE-2026-60675 vulnerability affects Oracle Applications Framework, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The vulnerability has a CVSS score of 8.8, indicati [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60674

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:08.330Z and has not been modified since then. The CVE-2026-60674 vulnerability in Oracle Business Intelligence Enterprise Edition allows unauthenticated attackers with network access via HTTP to compromise the system. This can lead to unauthorized access to critical data or complete access [truncated]