Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via RMI to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Interaction Blending accessible data as well as unauthorized read access to a subset of Oracle Interaction Blending accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Interaction Blending. CVSS 3.1 Base Score 4.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Tue, 04 Aug 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Data Modification, Read Access, and Partial Denial of Service via RMI in Oracle Interaction Blending |
Sat, 01 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Data Modification, Read Access, and Partial Denial of Service via RMI in Oracle Interaction Blending |
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High‑Privilege RMI Vulnerability in Oracle Interaction Blending | |
| Weaknesses | CWE-287 |
Fri, 24 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High‑Privilege RMI Vulnerability in Oracle Interaction Blending | |
| Weaknesses | CWE-284 CWE-287 |
|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via RMI to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Interaction Blending accessible data as well as unauthorized read access to a subset of Oracle Interaction Blending accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Interaction Blending. CVSS 3.1 Base Score 4.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L). | |
| First Time appeared |
Oracle
Oracle interaction Blending |
|
| CPEs | cpe:2.3:a:oracle:interaction_blending:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle interaction Blending |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:37:06.963Z
Updated: 2026-07-24T18:28:14.659Z
Reserved: 2026-07-08T15:51:55.594Z
Link: CVE-2026-60832
Updated: 2026-07-24T18:28:10.821Z
No data.
No data.