Vulnerability in Oracle E-Business Suite Maintenance Component
CVE-2026-60717

5.4MEDIUM

What is CVE-2026-60717?

The vulnerability affects the Oracle Complex Maintenance, Repair and Overhaul component of the Oracle E-Business Suite. It is caused by improper access control, enabling a low-privileged attacker with network access to exploit the system via HTTP. Successful exploitation may allow unauthorized actions, such as the ability to insert, update, or delete data, as well as unauthorized read access to sensitive information within the product. This presents significant risks to the confidentiality and integrity of accessible data managed by the affected component.

Affected Version(s)

Oracle Complex Maintenance, Repair and Overhaul 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.