CVE-2026-60683: High severity Oracle Oracle E-Business Suite vulnerability
Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. While the vulnerability is in Oracle Process Manufacturing Regulatory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60683?
The severity of CVE-2026-60683 is rated as high, with a score of 7.7.
How do I fix CVE-2026-60683?
To fix CVE-2026-60683, apply the latest security patches provided by Oracle for affected versions of the Oracle E-Business Suite.
Who is affected by CVE-2026-60683?
CVE-2026-60683 affects users of Oracle E-Business Suite versions 12.2.3 to 12.2.15.
What type of access is required to exploit CVE-2026-60683?
CVE-2026-60683 can be exploited by a low privileged attacker with network access via HTTP.
What are the potential impacts of CVE-2026-60683?
The potential impacts of CVE-2026-60683 include the compromise of sensitive data due to its critical vulnerability.