Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Sat, 01 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass in Oracle Applications Framework Search Bean Leading to Compromise | |
| Weaknesses | CWE-284 |
Thu, 30 Jul 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege HTTP Exploit Compromising Oracle Applications Framework | |
| Weaknesses | CWE-284 |
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege HTTP Exploit Compromising Oracle Applications Framework | |
| Weaknesses | CWE-284 |
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle applications Framework |
|
| CPEs | cpe:2.3:a:oracle:applications_framework:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle applications Framework |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:36:30.562Z
Updated: 2026-07-24T19:19:21.896Z
Reserved: 2026-07-08T15:51:55.577Z
Link: CVE-2026-60676
No data.
No data.
No data.