PatchSiren

Oracle CVE debriefs · Page 12

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle CVE published 2026-07-21

CVE-2026-61020

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:33.573Z and has not been modified since then. The CVE-2026-61020 vulnerability affects Oracle Customers Online, a component of Oracle E-Business Suite, specifically versions 12.2.3-12.2.15. It is an easily exploitable vulnerability that allows low-privileged attackers with network access vi [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61019

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:33.467Z and has not been modified since then. CVE-2026-61019 is a high-severity vulnerability in Oracle Customers Online, with a CVSS score of 8.1. It allows low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. Affected versions include 12. [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61014

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:33.243Z and has not been modified since then. CVE-2026-61014 is a high-severity vulnerability in Oracle Inventory Management, a component of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and allows low-privileged attackers with network access via HTTP to comprom [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-61000

CVE-2026-61000 is a vulnerability in Oracle Process Manufacturing Systems, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 8.1 and allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. This vulnerability affects versions 12.2.3-12.2.15 of Oracle Process M [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60999

The CVE-2026-60999 vulnerability affects Oracle Data Integrator version 14.1.2.0.0, allowing unauthenticated attackers with network access via HTTPS to compromise the system. This vulnerability has a CVSS 3.1 Base Score of 9.8, indicating high impacts on Confidentiality, Integrity, and Availability. Organizations should prioritize patching to prevent potential system takeovers. The CVE record was publishe [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60988

The CVE-2026-60988 record indicates a difficult-to-exploit vulnerability in Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and allows a low-privileged attacker with network access via HTTP to potentially compromise the system. Successful attacks can result in takeover of Oracle Project Portfolio Analysis. The CVSS 3.1 Base Score [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60987

CVE-2026-60987 is a vulnerability in Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. The vulnerability class is related to internal operations and allows low-privileged attackers with network access via HTTP to compromise the system. The likely operational impact includes unauthorized creation, deletion, or modification access to critical data or all Oracle Project Portfolio Ana [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60986

The CVE-2026-60986 vulnerability affects Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the system. The potential impact includes unauthorized creation, deletion, or modification access to critical data or all Oracle Project Portfolio Analysis acc [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60984

CVE-2026-60984 is a vulnerability in Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 7.1 and can be exploited by low-privileged attackers with network access via HTTP, potentially leading to unauthorized data modifications or access. Organizations should review their deployments and apply patches from Oracle. The CVE record was published on [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60978

The CVE-2026-60978 vulnerability affects the Oracle Scripting product of Oracle E-Business Suite, specifically versions 12.2.3-12.2.15. This vulnerability is classified as easily exploitable, allowing high privileged attackers with network access via HTTP to compromise Oracle Scripting. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60963

CVE-2026-60963 is a high-severity vulnerability affecting Oracle E-Business Suite, specifically the Oracle Treasury component. This vulnerability has a CVSS score of 8.1 and can be exploited by a low-privileged attacker with network access via HTTP. The vulnerability allows for unauthorized creation, deletion, or modification access to critical data or all Oracle Treasury accessible data, as well as unaut [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60953

The CVE-2026-60953 vulnerability is an easily exploitable issue in Oracle Telecommunications Billing Integrator, a component of Oracle E-Business Suite. This vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data or complete access to all Oracle Telecommunications Billing [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60948

The CVE-2026-60948 vulnerability affects Oracle Learning Management, a component of Oracle E-Business Suite. This vulnerability, classified under internal operations, allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can lead to unauthorized creation, deletion, or modification access to critical data or all Oracle Learning Management accessible data, [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60945

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:29.263Z and has not been modified since then. The CVE-2026-60945 vulnerability is in the Oracle Learning Management product of Oracle E-Business Suite, specifically in the Internal Operations component. It affects versions 12.2.3-12.2.15 and has a CVSS 3.1 Base Score of 7.3, indicating high [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60943

The CVE-2026-60943 vulnerability is a difficult-to-exploit vulnerability in Oracle Service Fulfillment Manager that allows low privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in takeover of Oracle Service Fulfillment Manager. The vulnerability has a CVSS 3.1 Base Score of 7.5 and affects Oracle Service Fulfillment Manager versions 12.2.3-12.2.15. [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60942

The CVE-2026-60942 vulnerability is an easily exploitable issue in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks of this vulnerability can re [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60939

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:28.660Z and has not been modified since then. The CVE-2026-60939 vulnerability affects Oracle Project Contracts versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the product and gain unauthorized read access to a subset of accessible data. [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60931

The CVE-2026-60931 vulnerability in Oracle Public Sector Financials is a difficult-to-exploit vulnerability that allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in a takeover of Oracle Public Sector Financials. The vulnerability affects versions 12.2.3-12.2.15 of the product. The CVSS score of 7.5 indicates a high severity. Evidence is l [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60930

The CVE-2026-60930 vulnerability affects Oracle Public Sector Financials, a component of Oracle E-Business Suite. This low-severity issue, classified as a vulnerability in the Internal Operations component, allows low-privileged attackers with network access via HTTP to potentially read a subset of accessible data. The CVSS 3.1 Base Score is 3.1, indicating limited impact. However, it is crucial for organ [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60929

The CVE-2026-60929 vulnerability affects Oracle Public Sector Financials versions 12.2.3-12.2.15, classified as a difficult-to-exploit vulnerability allowing low-privileged attackers with network access via HTTP to compromise the product. This could lead to unauthorized update, insert, or delete access to some accessible data. The CVSS 3.1 Base Score is 3.1, indicating low severity. Organizations should v [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60917

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:26.817Z and has not been modified since then. The CVE-2026-60917 vulnerability is an easily exploitable issue in Oracle Inventory Management's Core Receiving component. It allows low-privileged attackers with network access via HTTP to compromise Oracle Inventory Management, leading to unau [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60911

The CVE-2026-60911 vulnerability affects Oracle Property Manager, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the system. Successful attacks require human interaction from a person other than the attacker and can impact additional products beyond Oracle Property Manager. The CVS [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60910

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:26.347Z and has not been modified since then. The CVE-2026-60910 vulnerability is an easily exploitable issue in Oracle Property Manager, a component of Oracle E-Business Suite. It affects versions 12.2.3-12.2.15 and allows high privileged attackers with network access via HTTP to compromis [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60908

The CVE-2026-60908 vulnerability affects Oracle Installed Base, specifically versions 12.2.3-12.2.15, and allows low-privileged attackers with network access via HTTP to compromise the system. This vulnerability has a high CVSS score of 7.1 and can lead to unauthorized access to critical data or complete access to all Oracle Installed Base accessible data, as well as unauthorized update, insert or delete [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60907

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:26.130Z and has not been modified since then. The CVE-2026-60907 vulnerability affects Oracle Installed Base versions 12.2.4-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise Oracle Installed Base, potentially leading to unauthorized data access or partia [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60904

The CVE-2026-60904 vulnerability affects Oracle Installed Base versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system. This vulnerability enables unauthorized creation, deletion, or modification access to critical data or all Oracle Installed Base accessible data, as well as unauthorized access to critical data or complete access to all Oracle Inst [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60898

The CVE-2026-60898 vulnerability affects Oracle Warehouse Management, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The CVSS 3.1 Base Score is 8.8, indicating high severity. Affected versions are 12.2.3-12.2.15. Organizations should rev [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60897

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:25.463Z and has not been modified since then. The vulnerability in Oracle Payroll, part of Oracle E-Business Suite, affects versions 12.2.3-12.2.15. It is an easily exploitable vulnerability that allows low-privileged attackers with network access via HTTP to compromise Oracle Payroll, pote [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60893

The CVE-2026-60893 vulnerability is a medium-severity issue affecting Oracle Payroll, a component of Oracle E-Business Suite. This vulnerability, classified under Internal Operations, impacts versions 12.2.3 through 12.2.15. It has a CVSS score of 6.5, indicating a significant confidentiality risk. The vulnerability allows low-privileged attackers with logon access to compromise Oracle Payroll, potentiall [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60891

The CVE-2026-60891 vulnerability is a difficult-to-exploit issue in Oracle Work in Process, a component of Oracle E-Business Suite. This vulnerability allows high privileged attackers with logon to the infrastructure to compromise the system, potentially resulting in unauthorized read access to a subset of Oracle Work in Process accessible data. The CVSS 3.1 Base Score is 1.9, indicating a low severity. O [truncated]