Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Mon, 27 Jul 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure HTTP Access in Oracle Price Protection Enables Unauthorized Data Access |
Fri, 24 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
ssvc
|
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Price Protection accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle price Protection |
|
| CPEs | cpe:2.3:a:oracle:price_protection:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle price Protection |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-07-24T18:26:10.201Z
Reserved: 2026-07-08T15:51:55.594Z
Link: CVE-2026-60835
Updated: 2026-07-24T18:26:04.465Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T11:45:05Z
Weaknesses