Vulnerability in Oracle Workflow Product of Oracle E-Business Suite
CVE-2026-60144

3.6LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60144?

The vulnerability in Oracle Workflow, a component of Oracle E-Business Suite, presents a significant risk allowing low-privileged attackers with access to the infrastructure where Oracle Workflow operates to exploit system functionalities. This exploitation could result in unauthorized modifications, insertions, or deletions of sensitive data accessible via Oracle Workflow. Furthermore, successful attacks may lead to a partial denial of service, disrupting workflow operations. The affected versions include 12.2.3 through 12.2.15, highlighting a need for organizations using these versions to address the security risks associated with this vulnerability.

Affected Version(s)

Oracle Workflow 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.