Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Collections. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Collections. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Tue, 04 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privileged Network Exploit in Oracle Advanced Collections Allows Full Takeover |
Sun, 02 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privileged Network Exploit in Oracle Advanced Collections Allows Full Takeover |
Tue, 28 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via HTTP in Oracle Advanced Collections |
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 CWE-287 CWE-306 |
|
| Metrics |
ssvc
|
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via HTTP in Oracle Advanced Collections | |
| Weaknesses | CWE-284 |
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Collections. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Collections. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle advanced Collections |
|
| CPEs | cpe:2.3:a:oracle:advanced_collections:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle advanced Collections |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:37:40.508Z
Updated: 2026-07-29T03:55:39.109Z
Reserved: 2026-07-08T15:51:55.606Z
Link: CVE-2026-60989
Updated: 2026-07-24T15:07:22.506Z
Status : Analyzed
Published: 2026-07-21T22:18:32.017
Modified: 2026-08-17T14:06:53.000
Link: CVE-2026-60989
No data.