CVE-2026-60936: Low severity Oracle Oracle Labor Distribution vulnerability
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Labor Distribution. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the partial denial of service risk by restricting network access to Oracle Labor Distribution’s HTTP endpoint to only trusted clients (e.g., limit inbound HTTP at the network/firewall/ACL).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60936?
The severity of CVE-2026-60936 is low, with a CVSS score of 3.1.
How do I fix CVE-2026-60936?
To fix CVE-2026-60936, you should apply the latest security patches provided by Oracle for affected versions of the Labor Distribution product.
What versions are affected by CVE-2026-60936?
The affected versions of the Oracle Labor Distribution product include versions 12.2.3 to 12.2.15.
Who can exploit CVE-2026-60936?
CVE-2026-60936 can be exploited by a low privileged attacker with network access via HTTP.
What type of impact does CVE-2026-60936 have?
CVE-2026-60936 has a low impact on availability, as it may lead to a compromise of the Oracle Labor Distribution system.