Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Sun, 02 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote HTTP Privilege Escalation in Oracle Bills of Material |
Sat, 01 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privileged HTTP Attack Enables Takeover of Oracle Bills of Material | |
| Weaknesses | CWE-200 CWE-269 |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 26 Jul 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privileged HTTP Attack Enables Takeover of Oracle Bills of Material | |
| Weaknesses | CWE-200 CWE-269 CWE-284 |
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle bills Of Material |
|
| CPEs | cpe:2.3:a:oracle:bills_of_material:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle bills Of Material |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:37:01.575Z
Updated: 2026-07-28T14:56:25.744Z
Reserved: 2026-07-08T15:51:55.592Z
Link: CVE-2026-60807
Updated: 2026-07-28T13:41:23.199Z
No data.
No data.