Junglewise Threat Intelligence

CVE-2026-60571: Oracle E-Business Suite data manipulation in SDP Number Portability

CVE-2026-60571 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle SDP Number Portability, Oracle E-Business Suite. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Installation component of Oracle SDP Number Portability, a tool used within Oracle E-Business Suite to manage telecommunications number portability. An attacker with basic user credentials can remotely modify or delete certain data and cause partial service disruptions. This could lead to inaccurate records or temporary unavailability of the number portability service.

Technical details

A vulnerability in the Installation component of Oracle SDP Number Portability (part of Oracle E-Business Suite) allows for unauthorized data manipulation and partial denial of service. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to perform unauthorized updates, insertions, or deletions of accessible data, as well as disrupt service availability. The vulnerability affects versions 12.2.3 through 12.2.15 and was addressed in the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle Corporation SDP Number Portability (Oracle E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats