Vulnerability in Oracle Workflow Product of Oracle E-Business Suite
CVE-2026-61247

4.8MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61247?

A security vulnerability exists in the Oracle Workflow component of Oracle E-Business Suite that could allow an unauthenticated attacker with network access via SMTP to compromise the system. This vulnerability allows unauthorized update, insertion, or deletion of data accessible through Oracle Workflow, and could also lead to a partial denial of service of the application. The affected versions range from 12.2.3 to 12.2.15, requiring users to review and implement the necessary security patches to protect their systems.

Affected Version(s)

Oracle Workflow 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.