CVE-2026-61247: Medium severity Oracle Oracle Workflow (Oracle E-Business Suite) vulnerability
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 4.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - Oracle Workflow (Workflow Notification Mailer)to a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61247?
The severity of CVE-2026-61247 is medium with a score of 4.8.
How do I fix CVE-2026-61247?
To mitigate CVE-2026-61247, upgrade to a supported version of Oracle E-Business Suite that is not affected by this vulnerability.
What systems are affected by CVE-2026-61247?
CVE-2026-61247 affects Oracle Workflow in Oracle E-Business Suite versions 12.2.3 to 12.2.15.
Can CVE-2026-61247 be exploited by an unauthenticated user?
Yes, CVE-2026-61247 can be exploited by an unauthenticated attacker with network access via SMTP.
What impact does CVE-2026-61247 have on Oracle Workflow?
CVE-2026-61247 allows an attacker to compromise Oracle Workflow, leading to potential unauthorized access or disruption.