Vulnerability in Oracle E-Business Suite's Enterprise Asset Management Component
CVE-2026-60760

4.2MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60760?

A vulnerability in Oracle Enterprise Asset Management allows a low-privileged attacker with network access to exploit weaknesses in the component's internal operations. This flaw enables unauthorized updates, insertions, or deletions of accessible data and grants access to sensitive information. The supported versions affected are from 12.2.3 to 12.2.15, highlighting the importance of prompt remediation. To enhance security, users are advised to apply available patches and monitor access controls.

Affected Version(s)

Oracle Enterprise Asset Management 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.