PatchSiren

Oracle CVE debriefs · Page 14

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle CVE published 2026-07-21

CVE-2026-60723

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:12.363Z and has not been modified since then. The vulnerability in Oracle Data Integrator, specifically in the Market Place component, affects versions 12.2.1.4.0 and 14.1.2.0.0, allowing low-privileged attackers with logon to the infrastructure where Oracle Data Integrator executes to comp [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60714

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:11.903Z and has not been modified since then. CVE-2026-60714 is a vulnerability in Oracle Price Protection, a component of Oracle E-Business Suite. This vulnerability allows low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. The affected [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60706

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:11.053Z and has not been modified since then. The CVE-2026-60706 vulnerability affects Oracle E-Business Suite versions 12.2.3-12.2.15 and allows low-privileged attackers with network access via HTTP to compromise Oracle Process Manufacturing Inventory. Successful attacks can result in unau [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60704

A high-severity vulnerability was discovered in Siebel CRM Cloud Applications, specifically in the Siebel Cloud Manager component. The vulnerability has a CVSS score of 7.5 and allows unauthenticated attackers to access critical data. Organizations using Siebel CRM Cloud Applications versions 22.3-26.5 should prioritize patching this vulnerability to prevent unauthorized data access. The vulnerability is [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60703

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:10.713Z and has not been modified since then. CVE-2026-60703 is a vulnerability in Oracle Interaction Blending, a component of Oracle E-Business Suite. The vulnerability allows a low-privileged attacker with logon access to compromise Oracle Interaction Blending, potentially resulting in un [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60695

The CVE-2026-60695 vulnerability affects the Internal Operations component of Oracle Enterprise Asset Management, a product within Oracle E-Business Suite. This vulnerability has a CVSS score of 5.9, indicating a medium severity level. It is difficult to exploit and requires high-privileged attackers to have network access via HTTP. Potential impacts include unauthorized creation, deletion, or modificatio [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60694

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:10.150Z and has not been modified since then. CVE-2026-60694 is a vulnerability in Oracle Enterprise Asset Management, allowing low-privileged attackers with network access via HTTP to compromise the system. Successful attacks require human interaction and can result in unauthorized update, [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60692

CVE-2026-60692 is a vulnerability in Oracle Enterprise Asset Management, a component of Oracle E-Business Suite. The vulnerability affects versions 12.2.3-12.2.15 and allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The CVE record was published on 2026-07-21T22:18:10.037Z. The vulnerability has a CVSS score of 8.8, indicating high seve [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60691

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:09.923Z and has not been modified since then. The CVE-2026-60691 vulnerability affects Oracle Content Manager, a component of Oracle E-Business Suite. The vulnerability has a CVSS 3.1 Base Score of 8.1, indicating a high severity level. It allows low-privileged attackers with network access [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60688

CVE-2026-60688 is a vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (component: Rules UI). Supported versions that are affected are 12.2.3-12.2.15. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Scheduler, potentially leading to unauthorized update, insert or delete access to some of Oracle Scheduler accessible data as well as [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60684

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:09.130Z and has not been modified since then. CVE-2026-60684 is a vulnerability in Oracle Applications Framework that allows low privileged attackers with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction and can result in unau [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60683

CVE-2026-60683 is a vulnerability in Oracle Process Manufacturing Regulatory Management, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 7.7 and allows low-privileged attackers with network access via HTTP to compromise the product and access critical data. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Process Manufactu [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60676

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:08.573Z and has not been modified since then. The CVE-2026-60676 vulnerability affects Oracle Applications Framework versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The vulnerability has a CVS [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60569

A medium-severity vulnerability was found in MySQL Cluster, affecting versions 8.0.0-8.0.47, 8.4.0-8.4.10, and 9.7.0-9.7.1. This issue, CVE-2026-60569, allows an unauthenticated attacker with logon to the infrastructure where MySQL Cluster executes to potentially compromise MySQL Cluster, leading to unauthorized access to critical data. The vulnerability has a CVSS 3.1 Base Score of 5.1, indicating a medi [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60567

A critical vulnerability was discovered in Oracle Identity Manager, specifically in the OIM Legacy UI component. The vulnerability is easily exploitable and allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete acc [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60560

A high-severity vulnerability was discovered in Oracle Identity Manager, a product of Oracle Fusion Middleware. The vulnerability is located in the REST WebServices component and affects versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker with network access via HTTP can easily exploit this vulnerability to compromise Oracle Identity Manager. Successful attacks can result in unauthorized creatio [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60559

A high-severity vulnerability was discovered in Oracle Access Manager, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60559, affects versions 12.2.1.4.0 and 14.1.2.1.0 of the product. It is an easily exploitable vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle Access Manager. Successful attacks can result in unauthorized a [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60534

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:53.170Z and has not been modified since then. The vulnerability is in Oracle Identity Manager Connector, affecting versions 12.2.1.4.0 and 14.1.2.1.0. It has a CVSS 3.1 Base Score of 7.7, indicating high severity. The vulnerability allows high privileged attackers with network access via HT [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60532

The CVE-2026-60532 vulnerability affects Oracle Identity Manager Connector, specifically versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Fusion Middleware. This critical vulnerability, with a CVSS 3.1 score of 9.8, allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to full system takeover. The vulnerability is easily exploitable and has high impacts on [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60529

A high-severity vulnerability was discovered in Oracle WebLogic Server, specifically in the Console component. The vulnerability affects versions 14.1.2.0.0 and 15.1.1.0.0. It allows high-privileged attackers with network access via HTTP to compromise the server, potentially leading to a takeover. The CVSS 3.1 Base Score is 7.2, indicating high confidentiality, integrity, and availability impacts. This vu [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60527

A high-severity vulnerability, CVE-2026-60527, was discovered in Oracle WebLogic Server, affecting versions 14.1.2.0.0 and 15.1.1.0.0. This vulnerability allows an unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise the server. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server acc [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60521

The CVE-2026-60521 vulnerability affects Oracle Advanced Pricing, a component of Oracle E-Business Suite. This vulnerability is classified as easily exploitable, allowing unauthenticated attackers with network access via HTTP to compromise the system. The potential impact includes unauthorized update, insert, or delete access to some accessible data and unauthorized read access to a subset of accessible d [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60520

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:51.603Z and has not been modified since then. CVE-2026-60520 is a vulnerability in Oracle Unified Directory's OUD Core component, allowing low-privileged attackers with network access via LDAP to compromise data integrity and confidentiality; CVSS 8.1 HIGH. The vulnerability affects version [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60519

The CVE-2026-60519 vulnerability is an easily exploitable issue in Oracle Unified Directory's OUD Core component. It allows high privileged attackers with network access via LDAP to compromise Oracle Unified Directory, potentially leading to takeover. The vulnerability has a CVSS 3.1 Base Score of 7.2, indicating high impacts on confidentiality, integrity, and availability. Affected versions are 12.2.1.4. [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60494

A high-severity vulnerability was discovered in JD Edwards EnterpriseOne General Ledger. This vulnerability, tracked as CVE-2026-60494, has a CVSS score of 7.0 and allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in a hang or frequently repeatable crash of JD Edwards EnterpriseOne General Ledger, as well as unauthorized update, insert, o [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60493

A vulnerability exists in JD Edwards EnterpriseOne Human Resources Management, a product of Oracle JD Edwards. The affected version is 9.2. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks can result in a takeover of JD Edwards EnterpriseOne Human Resources Management. The vulnerability ha [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60468

CVE-2026-60468 is a high-severity vulnerability in Oracle Fusion Middleware's WebCenter Content: Imaging product, specifically in the Core component. The vulnerability has a CVSS score of 7.1 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. The vu [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60467

A high-severity vulnerability was discovered in Oracle Fusion Middleware's WebCenter Content: Imaging product, specifically in the Core component. The vulnerability, tracked as CVE-2026-60467, has a CVSS score of 7.5 and allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks require human interaction from a person other than the attacker and can result i [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60437

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:46.170Z and has not been modified since then. This vulnerability affects Oracle Unified Directory, a component of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.1.0. It allows high privileged attackers with network access via LDAP to compromise Oracle Unified Director [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60436

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:46.057Z and has not been modified since then. The CVE-2026-60436 vulnerability is an easily exploitable issue in Oracle Unified Directory that allows unauthenticated attackers with network access via LDAP to compromise Oracle Unified Directory, resulting in unauthorized ability to cause a h [truncated]