Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Tue, 04 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High Privilege Access Control Violation in Oracle Cost Management Leads to Full Application Takeover |
Sun, 02 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High Privilege Access Control Violation in Oracle Cost Management Leads to Full Application Takeover |
Tue, 28 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High Privilege Remote Compromise via HTTP in Oracle Cost Management |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High Privilege Remote Compromise via HTTP in Oracle Cost Management |
Wed, 22 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle cost Management |
|
| CPEs | cpe:2.3:a:oracle:cost_management:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle cost Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:39:24.917Z
Updated: 2026-07-22T17:52:13.302Z
Reserved: 2026-07-08T15:52:20.747Z
Link: CVE-2026-61328
Updated: 2026-07-22T17:52:09.204Z
Status : Undergoing Analysis
Published: 2026-07-21T22:19:01.127
Modified: 2026-07-23T18:29:34.653
Link: CVE-2026-61328
No data.