CVE-2026-61035: High severity Oracle Oracle E-Business Suite (Internal Operations) - Oracle Financials for the Americas vulnerability
Vulnerability in the Oracle Financials for the Americas product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Financials for the Americas. Successful attacks of this vulnerability can result in takeover of Oracle Financials for the Americas. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - Oracle Financials for the Americas (Internal Operations)to a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61035?
CVE-2026-61035 has a high severity rating of 7.2.
How do I fix CVE-2026-61035?
To fix CVE-2026-61035, apply the latest security patches provided by Oracle for affected versions of Oracle E-Business Suite.
Who is affected by CVE-2026-61035?
CVE-2026-61035 affects users of Oracle Financials for the Americas in the Oracle E-Business Suite version 12.2.3 to 12.2.15.
What are the potential impacts of CVE-2026-61035?
CVE-2026-61035 allows a high privileged attacker with network access to compromise Oracle Financials systems, leading to potential data breaches.
What component of Oracle E-Business Suite is affected by CVE-2026-61035?
CVE-2026-61035 specifically affects the Internal Operations component of Oracle Financials for the Americas.