Vulnerability in Oracle E-Business Suite's Marketing Component
CVE-2026-61277

6.3MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61277?

This vulnerability in the Oracle Marketing component of Oracle E-Business Suite allows low privileged attackers with network access via HTTP to potentially manipulate accessible data. The exploit can lead to unauthorized updates, inserts, and deletions of data within Oracle Marketing, making sensitive information at risk. Furthermore, attackers may gain unauthorized read access to certain subsets of data and could induce a partial denial of service, adversely affecting the availability of the marketing services. Users of affected versions from 12.2.3 to 12.2.15 should take immediate action to mitigate this risk.

Affected Version(s)

Oracle Marketing 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.