PatchSiren

Oracle Corporation CVE debriefs · Page 30

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60632

A critical vulnerability was discovered in Oracle WebCenter Content, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60632, affects versions 12.2.1.4.0 and 14.1.2.0.0. It allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks require human interaction and can significantly impact additional products. The vulnerability can re [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60631

A critical vulnerability was discovered in Oracle WebCenter Content, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60631, affects versions 12.2.1.4.0 and 14.1.2.0.0. It is an easily exploitable vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60630

A vulnerability was discovered in Oracle APEX (component: Installation) affecting versions 24.1, 24.2, and 26.1. This easily exploitable vulnerability allows a low-privileged attacker with logon to the infrastructure where Oracle APEX executes to compromise Oracle APEX, potentially leading to unauthorized access to critical data or complete access to all Oracle APEX accessible data. The vulnerability has [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60629

A high-severity vulnerability was discovered in Oracle JDeveloper, affecting versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data and update, insert, or delete access to some Oracle JDeveloper accessible data. The vulnerability is tracked as CVE-2026-60629 a [truncated]

LOW Oracle Corporation CVE published 2026-07-21

CVE-2026-60628

A low-severity vulnerability was found in JD Edwards EnterpriseOne Tools, specifically in the Installation Security component, affecting version 9.2.26.3. The vulnerability has a CVSS score of 3.7 and a CVSS vector of CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N. It is difficult to exploit and requires human interaction. Successful attacks can result in unauthorized update, insert, or delete access to som [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60626

A medium-severity vulnerability, CVE-2026-60626, was found in JD Edwards EnterpriseOne Tools. This vulnerability has a CVSS score of 6.0 and allows high-privileged attackers with logon access to compromise the system, potentially impacting additional products and allowing unauthorized data modifications. The vulnerability is in the Installation Security component of JD Edwards EnterpriseOne Tools version [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60625

A high-severity vulnerability was discovered in Oracle Data Integrator, specifically in the Studio component. The vulnerability is easily exploitable by a low-privileged attacker with logon access to the infrastructure where Oracle Data Integrator executes, potentially leading to a takeover of Oracle Data Integrator. This vulnerability affects Oracle Data Integrator versions 12.2.1.4.0 and 14.1.2.0.0. The [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60624

A medium-severity vulnerability was found in MySQL Connectors, specifically in the Connector/J component. The vulnerability, tracked as CVE-2026-60624, has a CVSS score of 6.5 and can be exploited by unauthenticated attackers with network access via multiple protocols. Successful attacks require human interaction and can result in a hang or frequently repeatable crash of MySQL Connectors. The vulnerabilit [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60623

A high-severity vulnerability was found in MySQL Connectors, specifically in the Connector/J component. The vulnerability has a CVSS score of 7.1 and can allow a low-privileged attacker with network access to compromise MySQL Connectors, potentially leading to unauthorized data access, modification, and partial denial of service. This vulnerability affects versions 9.7.0-9.7.1 and has a CVSS Vector of (CV [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60622

A high-severity vulnerability was found in the Security Framework component of Oracle JDeveloper. The vulnerability has a CVSS score of 7.5 and can allow unauthenticated attackers with network access via HTTP to compromise Oracle JDeveloper, potentially leading to unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. The vulnerability affects Oracle JDeveloper v [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60621

A high-severity vulnerability was identified in JD Edwards EnterpriseOne Tools, specifically in the Web Runtime Security component. This vulnerability, CVE-2026-60621, has a CVSS score of 8.1 and allows unauthenticated attackers with network access via HTTP to potentially take over the system. The vulnerability is difficult to exploit and affects version 9.2.26.3 of JD Edwards EnterpriseOne Tools. Organiz [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60620

A vulnerability was discovered in JD Edwards EnterpriseOne Configurator. The vulnerability has a CVSS score of 6.4, indicating a medium severity level. It is difficult to exploit and requires low privileged attacker with network access via HTTP. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash of JD Edwards EnterpriseOne Configurator as well as unauthori [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60619

A high-severity vulnerability was discovered in JD Edwards EnterpriseOne HCM Foundation, a product of Oracle JD Edwards. The vulnerability, tracked as CVE-2026-60619, has a CVSS score of 7.5 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of the affected system. This vulnerability is difficult to exploit and affects version 9.2 of the produ [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60618

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:02.253Z and has not been modified since then. CVE-2026-60618 is a vulnerability in JD Edwards EnterpriseOne Procurement and Subcontract Management (component: Procurement). The supported version 9.2 is affected. An easily exploitable vulnerability allows a low-privileged attacker with netwo [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60617

A difficult-to-exploit vulnerability in PeopleSoft Enterprise CS Campus Community allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data, as well as unauthorized read access to a subset of PeopleSoft Ente [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60616

A vulnerability was discovered in PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft. The supported version that is affected is 9.2.38. This difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks can result in unauthorized access to critical data or complete access to al [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60615

The CVE record for CVE-2026-60615 was published on 2026-07-21T22:18:01.910Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft, specifically version 9.2.38. It is a security vulnerability that allows unauthenticated attackers with network access via HTTP to compromise th [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60614

A vulnerability was discovered in PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data). The supported version that is affected is 9.2.38. This difficult to exploit vulnerability allows a low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks can result in unauthorized creation, deletion or [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60613

A vulnerability was discovered in PeopleSoft Enterprise CS Student Records, a product of Oracle PeopleSoft. The affected component is Research Tracking, and the supported version is 9.2.38. This vulnerability is difficult to exploit and requires a high-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks can result in a takeover of Peo [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60612

A vulnerability was discovered in PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans). The supported version that is affected is 9.2.38. This MEDIUM severity vulnerability, with a CVSS score of 6.8, allows a low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Financial Aid. Successful attacks can result in unauthorized c [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60611

A vulnerability was discovered in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The affected version is 9.2.38. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community, potentially leading to unauthorized read access to a subset of accessible data.

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60610

A vulnerability was discovered in PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft. The supported version that is affected is 9.2.38. This difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data o [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60609

A vulnerability was found in PeopleSoft Enterprise CS Campus Community 9.2.38, a product of Oracle PeopleSoft. This easily exploitable vulnerability allows low-privileged attackers with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community, potentially leading to unauthorized access to critical data. The vulnerability is located in the Communication component and has been assign [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60608

A vulnerability was discovered in PeopleSoft Enterprise CS Financial Aid 9.2.38, allowing low-privileged attackers with logon access to compromise the system, leading to unauthorized data creation, deletion, modification, and read access. This vulnerability has a CVSS score of 6.1 and affects PeopleSoft Enterprise CS Financial Aid 9.2.38. The vulnerability is classified as a medium severity issue, and org [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60607

A vulnerability was discovered in PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft. The vulnerability is in the FM Need Analysis Calculator component. The supported version that is affected is 9.2.38. This vulnerability allows low-privileged attackers with logon to the infrastructure where PeopleSoft Enterprise CS Financial Aid executes to compromise PeopleSoft Enterprise CS Financial A [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60606

CVE-2026-60606 is a critical vulnerability in PeopleSoft Enterprise CC Common Application Objects 9.2, allowing unauthenticated attackers with network access via HTTP to compromise the system. The vulnerability enables unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to sensitive data. Organizations using PeopleSoft Enterprise CC Common Application Objects [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60605

A high-severity vulnerability was found in PeopleSoft Enterprise CS Student Records, specifically in the Higher Ed Statistics Agency - UK HESA component of version 9.2.38. The vulnerability has a CVSS score of 7.5 and allows unauthenticated attackers to access critical data via HTTP. This vulnerability is easily exploitable and can result in unauthorized access to critical data or complete access to all P [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60604

A vulnerability was discovered in PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft. The supported version that is affected is 9.2.38. This difficult to exploit vulnerability allows a low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks can result in takeover of PeopleSoft Enterprise CS Campus Community. The v [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60603

A high-severity vulnerability was found in PeopleSoft Enterprise CS Student Records, specifically in the Australian Features component of version 9.2.38. The vulnerability has a CVSS score of 8.8 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of the affected system. This vulnerability has high confidentiality, integrity, and availability i [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60602

A high-severity vulnerability, tracked as CVE-2026-60602, was discovered in Oracle PeopleSoft Enterprise CS Student Financials, specifically in the Billing component of version 9.2.38. The vulnerability has a CVSS score of 8.8 and allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in a takeover of PeopleSoft Enterprise CS Student Financials [truncated]