Vulnerability in Oracle Enterprise Asset Management by Oracle
CVE-2026-60694

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60694?

A vulnerability in Oracle Enterprise Asset Management allows low privileged attackers with network access via HTTP to potentially compromise the system. This could lead to unauthorized update, insert, or delete access to Oracle's Enterprise Asset Management data, as well as unauthorized read access to certain data subsets. Successfully exploiting this vulnerability may require human interaction from someone other than the attacker, which can significantly broaden the impact of the attack across additional products. The vulnerability primarily affects supported versions ranging from 12.2.3 to 12.2.15.

Affected Version(s)

Oracle Enterprise Asset Management 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.