CVE-2026-61037: High severity Oracle Oracle E-Business Suite - Oracle Loans vulnerability
Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data as well as unauthorized access to critical data or complete access to all Oracle Loans accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61037?
The severity of CVE-2026-61037 is rated high with a score of 8.1.
How do I fix CVE-2026-61037?
To fix CVE-2026-61037, apply the latest security patches provided by Oracle for the affected versions of Oracle E-Business Suite.
What is the risk level associated with CVE-2026-61037?
The risk level associated with CVE-2026-61037 is assessed as medium, with a score of 60.
What components of Oracle E-Business Suite are affected by CVE-2026-61037?
CVE-2026-61037 affects the Oracle Loans component of Oracle E-Business Suite.
Who can exploit CVE-2026-61037?
CVE-2026-61037 can be exploited by low privileged attackers with network access via HTTP.