PatchSiren

Oracle CVE debriefs · Page 15

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60434

The CVE-2026-60434 vulnerability affects Oracle Transportation Management version 6.5.3, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized read access to a subset of accessible data. This vulnerability is considered easily exploitable and has a CVSS 3.1 Base Score of 4.3, indicating a medium severity level. The CVE record was publi [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60433

The CVE-2026-60433 vulnerability in Oracle Transportation Management (component: Integration) allows high privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Transportation Management accessible data as well as unauthorized access to critical data or complete acce [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60430

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:45.500Z and has not been modified since then. The CVE-2026-60430 vulnerability is an easily exploitable issue in Oracle Unified Directory's OUD Core component. It allows low-privileged attackers with network access via LDAP to compromise the directory, potentially leading to takeover. The v [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60429

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:45.357Z and has not been modified since then. The CVE-2026-60429 vulnerability affects Oracle Unified Directory, allowing low-privileged attackers with network access via LDAP to compromise the system, potentially impacting additional products. The CVSS score is 9.9, indicating critical sev [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60427

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:45.130Z and has not been modified since then. The vulnerability in Oracle Unified Directory (component: OUD Core) allows an unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory, potentially impacting additional products. Successful attacks can result [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60424

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:44.797Z and has not been modified since then. Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60423

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:44.680Z and has not been modified since then. The CVE-2026-60423 vulnerability is an easily exploitable issue in Oracle Unified Directory's OUD Core component. It allows low-privileged attackers with network access via LDAP to compromise the directory, potentially leading to takeover. The v [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60422

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:44.557Z and has not been modified since then. The CVE-2026-60422 vulnerability affects Oracle Unified Directory's OUD Core component, allowing low-privileged attackers with network access via LDAP to compromise data integrity and availability. Successful attacks can result in unauthorized c [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60421

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:44.443Z and has not been modified since then. The CVE-2026-60421 vulnerability affects Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0. It is a difficult-to-exploit vulnerability that allows low privileged attackers with network access via LDAP to compromise the system. Successf [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60418

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:44.090Z and has not been modified since then. The CVE-2026-60418 vulnerability is an easily exploitable issue in Oracle Unified Directory's OUD Core component, allowing high privileged attackers with network access via LDAP to compromise the system, resulting in takeover. The vulnerability [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60417

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:43.980Z and has not been modified since then. This vulnerability affects Oracle Unified Directory, specifically the OUD Core component. It is a difficult-to-exploit vulnerability that allows unauthenticated attackers with network access via LDAP to compromise Oracle Unified Directory, poten [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60416

A difficult-to-exploit vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine) allows unauthenticated attackers with network access via HTTP to potentially compromise Oracle Access Manager. Successful attacks can result in takeover of Oracle Access Manager. The CVSS 3.1 Base Score is 8.1 (Confidentiality, Integrity and Availability impacts). This v [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60402

The CVE-2026-60402 vulnerability is a critical issue in the Oracle TimesTen In-Memory Database product, specifically in the Kubernetes Operator component. This vulnerability has a CVSS score of 9.9 and can be easily exploited by low-privileged attackers with network access via HTTPS, potentially leading to a complete takeover of the TimesTen In-Memory Database. The affected version is 26.1.1.1.0. Oracle T [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60400

The CVE-2026-60400 vulnerability is in the Admin Server Executable component of Oracle GoldenGate, a high-severity issue allowing low-privileged attackers with network access via HTTPS to potentially take over the system. Affected versions include 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1. Oracle GoldenGate administrators should review and apply security patches, restrict network access, and moni [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60356

The CVE-2026-60356 vulnerability is in the Authentication Engine component of Oracle Access Manager, a critical product within Oracle Fusion Middleware. This vulnerability has a CVSS score of 8.6, indicating high severity, and can be exploited by unauthenticated attackers with network access via HTTP. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Ac [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60354

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:38.590Z and has not been modified since then. The CVE-2026-60354 vulnerability affects Oracle JDeveloper, specifically versions 12.2.1.4.0 and 14.1.2.0.0. It is a difficult-to-exploit vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle JDeve [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60353

The CVE-2026-60353 vulnerability affects Oracle JDeveloper, specifically versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability is difficult to exploit and allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized read access to a subset of accessible data. The vulnerability has a CVSS score of 3.1 and is considered low severity. Oracle JDe [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60352

The CVE-2026-60352 vulnerability affects Oracle JDeveloper, specifically versions 12.2.1.4.0 and 14.1.2.0.0. It is a difficult-to-exploit vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle JDeveloper, resulting in unauthorized read access to a subset of Oracle JDeveloper accessible data. The CVSS score is 3.7, indicating low severity. This vulnerability i [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60351

The CVE-2026-60351 vulnerability affects Oracle JDeveloper, specifically the ADF Faces component. This vulnerability is difficult to exploit and allows unauthenticated attackers with network access via HTTP to compromise Oracle JDeveloper, potentially leading to unauthorized data access. The CVSS score is 4.8, indicating a medium severity vulnerability. Organizations should review their deployments and co [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60350

The CVE-2026-60350 vulnerability is a security issue in the Oracle JDeveloper product of Oracle Fusion Middleware, specifically in the ADF Faces component. It affects versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability is easily exploitable by a low-privileged attacker with logon access to the infrastructure where Oracle JDeveloper executes, potentially leading to unauthorized access to critical data o [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60342

A vulnerability was discovered in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager, potentially leading to unauthorized read access to a subset of Oracle Access Manager [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60339

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:37.030Z and has not been modified since then. The NVD entry is currently Analyzed. Oracle Project Manufacturing users and administrators should be aware of this vulnerability and take necessary actions to mitigate potential risks. Affected operators, platforms, and security teams should rev [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-60338

The CVE-2026-60338 vulnerability affects Oracle Project Manufacturing V16, a component of Oracle E-Business Suite. This vulnerability is difficult to exploit and requires a low-privileged attacker with logon access to the infrastructure where Oracle Project Manufacturing executes. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle Project Manufacturing accessib [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60337

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:36.807Z and has not been modified since then. The CVE-2026-60337 vulnerability affects Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. This vulnerability requires high privileges and logon to the infrastructure, allowing unauthori [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60336

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:36.707Z and has not been modified since then. The CVE-2026-60336 vulnerability affects Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. It allows high privileged attacker with logon to the infrastructure where Oracle Project Manufa [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60333

A critical vulnerability was discovered in Oracle Access Manager, a product of Oracle Fusion Middleware, specifically in the Authentication Engine component. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 and allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in a takeover of Oracle Access Manager. The vulnerability has a CVS [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60330

A high-severity vulnerability was discovered in Oracle Identity Manager, specifically in the OIM Legacy UI component. This vulnerability, tracked as CVE-2026-60330, has a CVSS score of 8.5 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a takeover of Oracle Identity Manager. The vulnerability affects Oracle Identity Manager versions 12.2.1.4.0 and 14. [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60328

A critical vulnerability was discovered in Oracle Access Manager, a product of Oracle Fusion Middleware. The vulnerability is located in the Authentication Engine component and affects versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Access Manager, potentially leading to a full takeover of the syst [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60326

A critical vulnerability was discovered in Oracle Access Manager, a product of Oracle Fusion Middleware. The vulnerability is located in the Authentication Engine component and affects versions 12.2.1.4.0 and 14.1.2.1.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Access Manager. Successful attacks can result in unauthorized crea [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60325

A high-severity vulnerability was discovered in Oracle Access Manager, a product of Oracle Fusion Middleware. The vulnerability, tracked as CVE-2026-60325, affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Access Manager. The vulnerability is rated as easily exploitable, allowing a low-privileged attacker with access to the physical communication segment attached to the hardware where Oracle Access Man [truncated]