PatchSiren

Oracle CVE debriefs · Page 17

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60234

A critical vulnerability was discovered in Oracle Coherence, a product of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. It allows unauthenticated attackers with network access via TCP to compromise Oracle Coherence, potentially leading to a takeover of the system. The CVSS 3.1 Base Score is 9.8, indicating a high impact on confidentiality, [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60233

A vulnerability was discovered in Oracle Coherence, a product of Oracle Fusion Middleware, specifically in the Core component. The affected version is 15.1.1.0.0. This vulnerability allows a low-privileged attacker with network access via TCP to compromise Oracle Coherence, potentially leading to a partial denial of service (partial DOS). The CVSS 3.1 Base Score is 4.3, indicating a medium severity. Organ [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60232

A critical vulnerability was discovered in Oracle Coherence, a product of Oracle Fusion Middleware. The vulnerability affects versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. It allows unauthenticated attackers with network access via HTTP to compromise Oracle Coherence, potentially leading to a takeover of the system. The CVSS 3.1 Base Score is 9.8, indicating a high impact on confidentiality, integrity, [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60204

A critical vulnerability was discovered in Oracle WebLogic Server, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. This vulnerability allows unauthenticated attackers with network access via T3 or IIOP to compromise the server, potentially leading to a takeover. The CVSS 3.1 Base Score is 9.8, indicating a high impact on confidentiality, integrity, and availability. The vulnerabilit [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60203

A high-severity vulnerability was found in Oracle WebLogic Server. This issue, tracked as CVE-2026-60203, has a CVSS 3.1 Base Score of 8.8, indicating a high level of risk. The vulnerability affects multiple versions of Oracle WebLogic Server, including 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, pot [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-60202

A critical vulnerability was discovered in Oracle WebLogic Server, affecting versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via T3 or IIOP to compromise the server, potentially leading to a takeover. The vulnerability, tracked as CVE-2026-60202, has a CVSS 3.1 Base Score of 9.8, indicating critical sev [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60176

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:18.513Z and has not been modified since then. CVE-2026-60176 is a vulnerability in Oracle Payments, affecting versions 12.2.3-12.2.15 of Oracle E-Business Suite. It allows low-privileged attackers with network access via HTTP to compromise Oracle Payments, potentially leading to unauthorize [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60172

The CVE-2026-60172 vulnerability is a difficult-to-exploit issue in Oracle Autonomous Health Framework that allows high privileged attackers with logon to the infrastructure to compromise the framework. Successful attacks require human interaction from a person other than the attacker and can result in takeover of Oracle Autonomous Health Framework. The vulnerability has a CVSS 3.1 Base Score of 6.3, indi [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-60170

The CVE-2026-60170 vulnerability in Oracle Hospitality Simphony's POS component allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data. Affected versions include 19.8-19.8.5, 19.9-19.9.3, and 19.10. The CVSS 3.1 Base Score is 7.5, indicating high severity due to confidentiality impacts. This vulnerability is easil [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60165

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:17.237Z and has not been modified since then. The CVE-2026-60165 vulnerability is a medium severity issue affecting Oracle Cost Management product of Oracle E-Business Suite (component: Enterprise Command Center) version V16. This vulnerability allows high privileged attacker with network a [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60154

The CVE-2026-60154 vulnerability affects the Oracle Application Object Library, a component of Oracle E-Business Suite. This medium-severity vulnerability, with a CVSS 3.1 Base Score of 5.4, allows low-privileged attackers with network access via HTTP to compromise the library. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data and unauthorized read acce [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-60146

A vulnerability was discovered in the Oracle Access Manager product of Oracle Fusion Middleware, specifically in the Authentication Engine component. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks require human interaction from a person other than the attacker an [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-47061

The CVE-2026-47061 vulnerability is in the JDBC component of Oracle Database Server, affecting versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2. This is a difficult-to-exploit vulnerability that allows unauthenticated attackers with access to the physical communication segment to compromise JDBC, potentially impacting additional products. Successful attacks require human interaction and can result in u [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-47060

The CVE-2026-47060 vulnerability affects the JDBC component of Oracle Database Server, impacting versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2. This vulnerability is easily exploitable and allows unauthenticated attackers with network access via Oracle Net to compromise JDBC. Successful attacks require human interaction from another person and can result in unauthorized creation, deletion, or modifi [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-47056

A critical vulnerability was discovered in Oracle Data Integrator, specifically in the Rest Service component. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It allows unauthenticated attackers with network access via HTTP to compromise Oracle Data Integrator, potentially impacting additional products. Successful attacks can result in a complete takeover of Oracle Data Integrator. The vulne [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-47046

CVE-2026-47046 is a high-severity vulnerability in the RDBMS component of Oracle Database Server versions 23.4.0-23.26.2. This vulnerability allows unauthenticated attackers with network access via Oracle Net to compromise RDBMS, potentially causing system crashes (complete DOS) and unauthorized data modifications (insert, update, delete). The CVSS 3.1 Base Score is 8.2, indicating high severity. Limited [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-47045

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:10.113Z and has not been modified since then. The vulnerability affects Oracle Database Server versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2, allowing high privileged attackers with network access via Oracle Net to compromise JDBC, requiring human interaction for successful attacks. O [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-47040

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:09.667Z and has not been modified since then. The CVE-2026-47040 vulnerability affects the Oracle Net Services component of Oracle Database Server, allowing unauthenticated attackers with network access via Oracle Net to compromise Oracle Net Services, potentially leading to unauthorized da [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-47039

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:09.547Z and has not been modified since then. The CVE-2026-47039 vulnerability is in the Java VM component of Oracle Database Server, affecting versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2. It is easily exploitable by low-privileged attackers with Create Session privilege and network [truncated]

LOW Oracle CVE published 2026-07-21

CVE-2026-47038

The CVE-2026-47038 vulnerability is a low-severity issue in the RDBMS component of Oracle Database Server, affecting versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2. It allows high privileged attackers with network access via Oracle Net to compromise RDBMS, potentially leading to unauthorized update, insert or delete access to some RDBMS accessible data. The vulnerability has a CVSS score of 2.7 and i [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-47019

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:07.567Z and has not been modified since then. The CVE-2026-47019 vulnerability affects Oracle Product Hub versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system, with CVSS score of 8.1 and Confidentiality and Integrity impacts. Evide [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-47014

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:06.977Z and has not been modified since then. CVE-2026-47014 is a high-severity vulnerability in Oracle Product Workbench, a component of Oracle E-Business Suite. The vulnerability has a CVSS 3.1 Base Score of 8.1 and can be exploited by low-privileged attackers with network access via HTTP [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-46999

The CVE-2026-46999 vulnerability is a difficult-to-exploit issue in the Oracle Enterprise Manager Base Platform product, specifically in the Discovery Framework component. It affects versions 13.5 and 24.1 of the platform. An unauthenticated attacker with network access via HTTPS can exploit this vulnerability to compromise the Oracle Enterprise Manager Base Platform. Successful attacks can result in unau [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-46983

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:03.347Z and has not been modified since then. The NVD entry is currently Analyzed. Organizations should verify their deployments and apply patches or mitigations as recommended by the vendor. Evidence is limited to public sources and may not reflect the full scope of affected systems or pot [truncated]

CRITICAL Oracle CVE published 2026-07-21

CVE-2026-46982

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:03.240Z and has not been modified since then. CVE-2026-46982 is a critical vulnerability in Oracle Retail Integration Bus, affecting version 14.1.3.2. It allows unauthenticated attackers with network access via HTTP to compromise the product, potentially leading to takeover. The vulnerabili [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-46981

The CVE-2026-46981 vulnerability affects Oracle Utilities Network Management System, specifically in the Mobile component. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system. The affected versions are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2. Successful attacks can result in una [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-46980

A vulnerability exists in Oracle Utilities Network Management System, specifically in the Mobile component. The affected versions are 2.5.0.1.0-2.5.0.1.17, 2.5.0.2.0-2.5.0.2.11, 2.6.0.1.0-2.6.0.1.12, 2.6.0.2.0-2.6.0.2.8, and 25.12.0.0.0-25.12.0.0.2. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to unauthorized read access to [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-46975

The CVE-2026-46975 vulnerability affects the RDBMS component of Oracle Database Server, specifically versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2. This is an easily exploitable vulnerability that allows unauthenticated attackers with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful [truncated]

HIGH Oracle CVE published 2026-07-21

CVE-2026-46954

A high-severity vulnerability was found in Oracle Human Resources, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-46954, has a CVSS score of 7.2 and can be easily exploited by high-privileged attackers with network access via HTTP, potentially leading to a takeover of Oracle Human Resources. The vulnerability is located in the Data Removal Tool component and affects version [truncated]

MEDIUM Oracle CVE published 2026-07-21

CVE-2026-34316

The CVE-2026-34316 vulnerability in Oracle Commerce Service Center 11.4.0 is an easily exploitable issue that allows unauthenticated attackers with network access via HTTP to compromise the service. The vulnerability requires human interaction from a person other than the attacker and can lead to unauthorized update, insert, or delete access to some of Oracle Commerce Service Center accessible data, as we [truncated]