Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Receivables. Successful attacks of this vulnerability can result in takeover of Oracle Receivables. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspujun2026.html |
|
History
Fri, 19 Jun 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SOAP Access Enables Application Takeover in Oracle Receivables |
Thu, 18 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SOAP Access Enables Takeover of Oracle Receivables | |
| Weaknesses | CWE-287 |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SOAP Access Enables Takeover of Oracle Receivables | |
| Weaknesses | CWE-284 CWE-287 CWE-306 |
|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Receivables. Successful attacks of this vulnerability can result in takeover of Oracle Receivables. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle receivables |
|
| CPEs | cpe:2.3:a:oracle:receivables:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle receivables |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-06-16T19:27:54.544Z
Updated: 2026-06-17T14:03:14.760Z
Reserved: 2026-05-18T15:55:10.312Z
Link: CVE-2026-46927
Updated: 2026-06-17T14:03:09.613Z
No data.
No data.