Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Lease and Finance Management accessible data as well as unauthorized read access to a subset of Oracle Lease and Finance Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Lease and Finance Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Tue, 04 Aug 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege Authorization Bypass in Oracle Lease and Finance Management Enable Data Modification and Partial Denial of Service |
Thu, 30 Jul 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege Authorization Bypass in Oracle Lease and Finance Management Enable Data Modification and Partial Denial of Service |
Tue, 28 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege Access to Data and Partial Denial of Service in Oracle Lease and Finance Management |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privilege Access to Data and Partial Denial of Service in Oracle Lease and Finance Management |
Wed, 22 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 CWE-284 CWE-306 |
|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Lease and Finance Management accessible data as well as unauthorized read access to a subset of Oracle Lease and Finance Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Lease and Finance Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L). | |
| First Time appeared |
Oracle
Oracle lease And Finance Management |
|
| CPEs | cpe:2.3:a:oracle:lease_and_finance_management:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle lease And Finance Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:39:32.832Z
Updated: 2026-07-22T16:29:54.379Z
Reserved: 2026-07-14T14:54:48.734Z
Link: CVE-2026-62474
Updated: 2026-07-22T16:29:50.598Z
No data.
No data.