PatchSiren

Oracle Corporation CVE debriefs · Page 32

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60558

A high-severity vulnerability was discovered in Oracle WebCenter Sites, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60558, has a CVSS score of 8.1 and can be exploited by unauthenticated attackers with network access via HTTP, potentially leading to a takeover of Oracle WebCenter Sites. The vulnerability is located in the WebCenter Sites component and has a CVSS Vector of [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60557

A vulnerability was discovered in Oracle WebCenter Sites, a product of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks require human interaction and can result in unauthorized access to critical data. The vulnerability has a medium severity with a CVSS score [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60556

A high-severity vulnerability was discovered in Oracle WebCenter Sites, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60556, has a CVSS score of 8.6 and allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites acce [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60555

A critical vulnerability was discovered in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. The vulnerability is easily exploitable, allowing unauthenticated attackers with network access via HTTP to compromise the site. Successful attacks can result in a complete takeover of Oracle WebCenter Sites. The vulnerability has a CVSS 3.1 Base Score of 9.8, indicating a high impact on confidentia [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60553

A high-severity vulnerability was discovered in Oracle WebCenter Sites, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60553, has a CVSS score of 8.7 and can be exploited by unauthenticated attackers with network access via HTTP. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle WebCenter Sites accessible [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60552

A critical vulnerability was identified in Oracle WebCenter Sites, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60552, has a CVSS 3.1 Base Score of 9.9, indicating a high impact on confidentiality, integrity, and availability. The vulnerability affects Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged attacker with netw [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60551

A critical vulnerability was identified in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. The vulnerability has been assigned a CVSS 3.1 Base Score of 9.8, indicating a high severity level. The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Sites, potential [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60550

A high-severity vulnerability was found in Oracle WebCenter Sites, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60550, has a CVSS score of 8.6 and allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Sites, potentially impacting additional products. This vulnerability is located in the WebCenter Sites component and is easily exploita [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60548

A high-severity vulnerability was found in Oracle SOA Suite's Integration Business Insight component, with a CVSS score of 7.7. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle SOA Suite, potentially impacting additional products. Organizations should prioritize patching to prevent data breaches. The CVE record and NVD entry provide further details.

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60547

A critical vulnerability was identified in Oracle Managed File Transfer, a component of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60547, has a CVSS 3.1 Base Score of 9.9, indicating a high severity level. It affects Oracle Managed File Transfer versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, poten [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60546

A high-severity vulnerability was found in Oracle SOA Suite's Integration Business Insight component. This vulnerability has a CVSS score of 7.2 and allows a high-privileged attacker with network access via HTTP to compromise Oracle SOA Suite, potentially leading to a takeover. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. Organizations should prioritize patching to prevent potential compromise. Th [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60545

A vulnerability was discovered in Oracle Managed File Transfer, a component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle Managed File Transfer. The vulnerability has a CVSS 3.1 Base Score of 8.8, indicating high confidentiality, integ [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60544

A high-severity vulnerability was found in Oracle SOA Suite, specifically in the B2B Engine component. The vulnerability is easily exploitable, allowing unauthenticated attackers with network access via HTTP to compromise Oracle SOA Suite. Successful attacks can result in unauthorized access to critical data and partial denial of service. This vulnerability has significant implications for data confidenti [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60543

The CVE-2026-60543 vulnerability affects the Oracle SOA Suite product, specifically the B2B Engine component. This vulnerability is difficult to exploit and allows unauthenticated attackers with network access via HTTP to compromise the suite, potentially leading to takeover. The CVSS score is 8.1, indicating high severity. Administrators and security teams should review and apply security patches, implem [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60542

A critical vulnerability was discovered in Oracle Business Process Management Suite, specifically in the Human Workflow component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged attacker with network access via T3 or IIOP, potentially leading to a complete takeover of the Oracle Business Process Management Suite. The v [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60541

A critical vulnerability was discovered in Oracle SOA Suite, specifically in the Enterprise Scheduling System component. This vulnerability, with a CVSS score of 9.8, can be exploited by an unauthenticated attacker with network access via HTTP. Successful exploitation could lead to a complete takeover of Oracle SOA Suite. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. Administrators and security tea [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60540

A critical vulnerability was discovered in Oracle SOA Suite, specifically in the Integration Business Insight component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a low-privileged attacker with network access via HTTP, potentially impacting additional products. Successful attacks could result in unauthorized creation, deletion, or [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60539

A high-severity vulnerability was found in Oracle SOA Suite, specifically in the Integration Business Insight component. The vulnerability has a CVSS score of 8.8 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle SOA Suite. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle SOA Suite. Administrators and security [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60538

CVE-2026-60538 is a critical vulnerability in the Oracle SOA Suite product's Enterprise Scheduling System, allowing unauthenticated network attackers to compromise the product with a CVSS score of 9.8. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. This vulnerability can lead to a complete takeover of Oracle SOA Suite. Oracle SOA Suite administrators and users should prioritize patching for these ve [truncated]

CRITICAL Oracle Corporation CVE published 2026-07-21

CVE-2026-60531

A critical vulnerability was discovered in Oracle Identity Manager Connector, a component of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60531, has a CVSS score of 9.9, indicating a high severity level. It affects versions 12.2.1.4.0 and 14.1.2.1.0 of the product. The vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60530

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:52.720Z and has not been modified since then. The CVE-2026-60530 vulnerability affects Oracle HTTP Server product of Oracle Fusion Middleware, specifically the mod_http2.so component. The supported version that is affected is 14.1.2.0.0. This easily exploitable vulnerability allows a low-pr [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60528

A high-severity vulnerability was discovered in Oracle WebLogic Server, affecting versions 14.1.2.0.0 and 15.1.1.0.0. This vulnerability, tracked as CVE-2026-60528, allows high-privileged attackers with network access via HTTP to compromise the server. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle WebLogic Server accessible data, as [truncated]

MEDIUM Oracle Corporation CVE published 2026-07-21

CVE-2026-60526

A medium-severity vulnerability was found in Oracle Java SE's Installation component. This issue affects Oracle Java SE versions 8u491 and 8u491-perf. The vulnerability is difficult to exploit and requires a low-privileged attacker with logon access to the infrastructure where Oracle Java SE executes. Successful attacks require human interaction from another person. If exploited, this vulnerability can le [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60525

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:52.177Z and has not been modified since then. Vulnerability in Oracle WebCenter Content product of Oracle Fusion Middleware, difficult to exploit, allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60523

The CVE-2026-60523 vulnerability affects Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, classified as a high-severity issue with a CVSS 3.1 Base Score of 8.7. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially impacting additional products. Successful attacks require human interaction and can result in unauthorized creation, deleti [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60522

The CVE-2026-60522 vulnerability is an easily exploitable issue in Oracle WebCenter Content, allowing low-privileged attackers with network access via HTTP to compromise the system. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data, as well as unauthorized update, insert, or delete access t [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60502

CVE-2026-60502 is a high severity vulnerability in Oracle Fusion Middleware WebCenter Content: Imaging. The vulnerability is classified as easily exploitable by a high privileged attacker with network access via T3, IIOP, and can result in takeover of WebCenter Content: Imaging. This vulnerability affects product versions 12.2.1.4.0 and 14.1.2.0.0. The CVSS score is 7.2, indicating high confidentiality, i [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60499

A high-severity vulnerability was discovered in JD Edwards EnterpriseOne Solution Advisor, a product of Oracle JD Edwards. The vulnerability has a CVSS score of 8.8 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of the affected system. The vulnerability is located in the Solution Advisor component of JD Edwards EnterpriseOne Solution Advis [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60498

A high-severity vulnerability, CVE-2026-60498, was discovered in JD Edwards EnterpriseOne Human Resources Management, a product of Oracle JD Edwards. This vulnerability, located in the Human Resources component of version 9.2, is difficult to exploit and allows low-privileged attackers with network access via JDENET to potentially take over the HRMS. The CVSS score of 7.5 indicates high severity, with imp [truncated]

HIGH Oracle Corporation CVE published 2026-07-21

CVE-2026-60497

A high-severity vulnerability was discovered in JD Edwards EnterpriseOne CRM Foundation with a CVSS score of 7.5. The vulnerability is difficult to exploit and allows a low-privileged attacker with network access to compromise the system. This vulnerability is located in the CRM Foundation component of JD Edwards EnterpriseOne. The CVSS vector is CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. Organizations [truncated]