CVE-2026-60775: Medium severity Oracle Oracle E-Business Suite (Pasta) vulnerability
Vulnerability in the Pasta product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Pasta executes to compromise Pasta. Successful attacks of this vulnerability can result in takeover of Pasta. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60775?
The severity of CVE-2026-60775 is rated as medium with a score of 6.7.
How do I fix CVE-2026-60775?
To fix CVE-2026-60775, it is recommended to apply the latest security patches provided by Oracle for affected versions of the E-Business Suite.
Which versions are affected by CVE-2026-60775?
CVE-2026-60775 affects supported versions of Oracle E-Business Suite from 12.2.3 to 12.2.15.
What is the risk associated with CVE-2026-60775?
CVE-2026-60775 has a risk score of 60, indicating it may allow a high-privileged attacker to compromise the Pasta component.
What type of vulnerability is CVE-2026-60775?
CVE-2026-60775 is classified as an easily exploitable vulnerability in the Internal Operations component of the Pasta product.