Junglewise Threat Intelligence

CVE-2026-60761: Oracle Applications DBA information disclosure in Internal Operations

CVE-2026-60761 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Applications Dba. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Applications DBA component of the Oracle E-Business Suite, which is used for managing and maintaining enterprise resource planning (ERP) databases. An attacker with low-level access to the underlying server could exploit this flaw to gain unauthorized access to sensitive business data. This could lead to a significant breach of confidentiality across multiple integrated Oracle products.

Technical details

This vulnerability affects the Internal Operations component of Oracle Applications DBA within Oracle E-Business Suite. It is classified as a local confidentiality impact bug that allows a low-privileged attacker with existing logon access to the infrastructure to compromise the DBA product. The exploit is characterized by a 'scope change' (S:C), meaning that while the vulnerability resides in the DBA component, it can be used to access data or impact other products within the environment. The attack requires no user interaction and has low complexity. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Applications DBA (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats