These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A medium-severity vulnerability was found in PeopleSoft Enterprise FIN Common Objects, specifically in the Security component. The vulnerability has a CVSS score of 4.4 and allows a low-privileged attacker with logon to the infrastructure to compromise PeopleSoft Enterprise FIN Common Objects. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized [truncated]
A high-severity vulnerability exists in Oracle PeopleSoft Enterprise FIN Project Costing, specifically in the Projects component of version 9.2. The vulnerability, tracked as CVE-2026-60600, has a CVSS score of 7.8 and can allow an unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Project Costing executes to compromise the system. Successful attacks require human in [truncated]
A high-severity vulnerability was discovered in PeopleSoft Enterprise CS Student Records, specifically in the Research Tracking component of version 9.2.38. The vulnerability has a CVSS score of 8.1 and can allow an attacker with low privileges and network access via HTTPS to compromise the system and access critical data. This could lead to unauthorized creation, deletion, or modification of critical dat [truncated]
A high-severity vulnerability was found in the Research Tracking component of PeopleSoft Enterprise CS Student Records 9.2.38. The vulnerability has a CVSS score of 7.5 and can allow a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to system takeover. This CVE was published on 2026-07-21 and is still undergoing analysis in the NVD. The vulnerability is d [truncated]
A high-severity vulnerability was discovered in Oracle PeopleSoft Enterprise FIN Cash Management, affecting version 9.2. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system, potentially impacting additional products. The vulnerability, tracked as CVE-2026-60597, has a CVSS 3.1 Base Score of 8.7, indicating a high level of severity. [truncated]
A low-severity vulnerability exists in PeopleSoft Enterprise FIN eSettlements, version 9.2. A high-privileged attacker with logon access can exploit this vulnerability to gain unauthorized read access to a subset of accessible data. The vulnerability has a CVSS 3.1 Base Score of 2.3, indicating low severity. The CVSS Vector is (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N). System administrators and secur [truncated]
A vulnerability was discovered in PeopleSoft Enterprise FIN Pay/Bill Management, a product of Oracle PeopleSoft. The affected version is 9.2. This vulnerability is easily exploitable by a low-privileged attacker with logon access to the infrastructure where PeopleSoft Enterprise FIN Pay/Bill Management executes. Successful attacks can result in unauthorized access to critical data or complete access to al [truncated]
A vulnerability was discovered in PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft, specifically in the Integration and Interfaces component. The supported version that is affected is 9.2.38. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community, potentially leading to system takeover. Successful attac [truncated]
The CVE-2026-60593 vulnerability affects PeopleSoft Enterprise FIN Staffing Front Office product of Oracle PeopleSoft, specifically version 9.2. This is an easily exploitable vulnerability allowing unauthenticated attackers with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office. Successful attacks can result in unauthorized creation, deletion, or modification access to [truncated]
A vulnerability was discovered in Oracle Enterprise Asset Management, a product of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and is classified as easily exploitable, allowing a low-privileged attacker with network access via HTTPS to compromise the system. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data, as well as una [truncated]
A vulnerability was discovered in Oracle Project Foundation, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-60587, has a CVSS 3.1 Base Score of 6.3, indicating a medium severity level. The vulnerability affects versions 12.2.3-12.2.15 of Oracle Project Foundation and can be exploited by a low-privileged attacker with network access via HTTP. Successful attacks can result in [truncated]
A high-severity vulnerability was found in MySQL Connectors, specifically in the Connector/J component. The vulnerability affects versions 9.7.0-9.7.1 and allows a low-privileged attacker with network access to compromise MySQL Connectors, potentially impacting additional products. The vulnerability has a CVSS score of 7.7 and is classified as HIGH severity. It can be easily exploited by low-privileged at [truncated]
A vulnerability exists in MySQL Server and MySQL Cluster products of Oracle MySQL, specifically in the Server: Replication component. The vulnerability is difficult to exploit and allows high privileged attackers with network access to compromise MySQL Server and MySQL Cluster. Successful attacks can result in takeover of MySQL Server and MySQL Cluster. The affected versions are MySQL Server: 8.4.0-8.4.10 [truncated]
A vulnerability was discovered in Oracle Transportation Management (component: CSV Management). The supported version affected is 6.5.3. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Transportation Management accessible da [truncated]
A vulnerability was discovered in the Oracle Transportation Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.5.3. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in the takeover of Oracle Transportation Management. T [truncated]
A vulnerability was discovered in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in unauthorized creatio [truncated]
A high-severity vulnerability was identified in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite. The vulnerability, which has a CVSS score of 7.5, is difficult to exploit and allows an unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise the framework [truncated]
A high-severity vulnerability was found in Oracle Enterprise Command Center Framework, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 8.8 and can be easily exploited by an unauthenticated attacker with access to the physical communication segment. Successful attacks can result in a takeover of Oracle Enterprise Command Center Framework. This vulnerability is located in the C [truncated]
A high-severity vulnerability was discovered in Oracle Enterprise Command Center Framework, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-60578, has a CVSS score of 7.6 and allows high privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Enterprise [truncated]
A high-severity vulnerability was discovered in Oracle Enterprise Command Center Framework, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-60576, has a CVSS score of 7.2 and can be easily exploited by high-privileged attackers with network access via HTTP, potentially leading to a takeover of the framework. This vulnerability is located in the Core component of Oracle Enter [truncated]
A vulnerability was discovered in Oracle Workflow, a component of Oracle E-Business Suite. The vulnerability is rated as medium severity with a CVSS score of 6.3. It affects versions 12.2.3-12.2.15 of Oracle Workflow. An attacker with low privileges and network access via HTTP could exploit this vulnerability to compromise Oracle Workflow, leading to unauthorized data access and partial denial of service.
A vulnerability was discovered in Oracle Content Manager, a component of Oracle E-Business Suite. The vulnerability is rated as Medium with a CVSS score of 6.3. It allows a low-privileged attacker with network access via HTTP to compromise Oracle Content Manager, potentially leading to unauthorized data access and partial denial of service. The vulnerability is located in the Cover Letter component of Ora [truncated]
A vulnerability exists in Oracle Partner Management, a component of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTPS to compromise Oracle Partner Management. Successful attacks can result in unauthorized update, insert or delete access to some accessible data, unauthorized read access to a subset of accessi [truncated]
A vulnerability was found in Oracle E-Business Suite Integrated SOA Gateway. The vulnerability is in the Web Service Provider component. Supported versions that are affected are 12.2.3-12.2.15. The vulnerability can be easily exploited by a low privileged attacker with network access via HTTP, allowing unauthorized update, insert or delete access to some accessible data as well as unauthorized read access [truncated]
A vulnerability was found in Oracle SDP Number Portability product of Oracle E-Business Suite. The affected versions are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle SDP Number Portability. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle SDP Number Portability accessible data and unauth [truncated]
A vulnerability was discovered in Oracle GoldenGate, specifically in the Libraries component, affecting versions 23.4-23.26.1. This easily exploitable vulnerability allows a low-privileged attacker with logon access to the infrastructure where Oracle GoldenGate executes, potentially leading to a takeover of Oracle GoldenGate. The CVSS 3.1 Base Score is 7.8, indicating a High severity level, with impacts o [truncated]
A critical vulnerability was discovered in Oracle WebCenter Portal, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60568, has a CVSS 3.1 Base Score of 9.9, indicating a high impact on confidentiality, integrity, and availability. The vulnerability affects Oracle WebCenter Portal versions 12.2.1.4.0 and 14.1.2.0.0. It is located in the Runtime Tools component and can be easil [truncated]
A critical vulnerability was discovered in Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Portal, potentially leading to a complete takeover of the system. The vulnerability has a CVSS 3.1 Base Score of 9.8, indicating a high impact on confidentiality, [truncated]
A critical vulnerability was discovered in Oracle WebCenter Portal, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60565, affects versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to a complete takeover of Oracle WebCenter Portal. The vulnerability has a CVSS 3.1 Base Score of 9.9, indi [truncated]
A critical vulnerability was discovered in Oracle WebCenter Portal, a product of Oracle Fusion Middleware, specifically in the Runtime Tools component. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle WebCenter Portal. The CVSS 3.1 Base Score is 9.9, indicating a hig [truncated]