Junglewise Threat Intelligence

CVE-2026-60724: Oracle E-Business Suite unauthorized data access in Customer Interaction History

CVE-2026-60724 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Customer Interaction History. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Outcome-Result component of Oracle Customer Interaction History, a tool within the Oracle E-Business Suite used to track customer engagements. An attacker with low-level user credentials can access the system over the network to view, modify, or delete certain customer interaction records. This could lead to unauthorized data manipulation or the exposure of sensitive customer history information.

Technical details

This vulnerability affects the Outcome-Result component of Oracle Customer Interaction History within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation enables unauthorized read access to a subset of data and unauthorized update, insert, or delete access to specific accessible data within the Customer Interaction History. The attack does not require user interaction and has a CVSS 3.1 base score of 5.4, impacting both confidentiality and integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Customer Interaction History (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats