Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
Thu, 13 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privilege HTTP Vulnerability Enables Unauthorized Data Access in Oracle Work in Process |
Wed, 12 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege Authorization Bypass in Oracle Work in Process | |
| Weaknesses | CWE-272 |
Tue, 04 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege Authorization Bypass in Oracle Work in Process | |
| Weaknesses | CWE-272 CWE-285 |
Tue, 04 Aug 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Access Control in Oracle Work in Process Allows Unauthorized Data Access and Modification | |
| Weaknesses | CWE-284 |
Thu, 30 Jul 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Access Control in Oracle Work in Process Allows Unauthorized Data Access and Modification | |
| Weaknesses | CWE-284 |
Tue, 28 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle Work in Process Vulnerability Enables Unauthorized Data Access with Low Privilege | |
| Weaknesses | CWE-200 CWE-284 |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle Work in Process Vulnerability Enables Unauthorized Data Access with Low Privilege | |
| Weaknesses | CWE-200 CWE-284 |
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Work in Process accessible data as well as unauthorized update, insert or delete access to some of Oracle Work in Process accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N). | |
| First Time appeared |
Oracle
Oracle work In Process |
|
| CPEs | cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle work In Process |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-07-24T17:37:30.028Z
Reserved: 2026-07-08T15:51:55.598Z
Link: CVE-2026-60886
No data.
Status : Analyzed
Published: 2026-07-21T22:18:24.593
Modified: 2026-07-28T19:46:34.330
Link: CVE-2026-60886
No data.
OpenCVE Enrichment
Updated: 2026-08-13T11:15:05Z