Junglewise Threat Intelligence

CVE-2026-60847: Oracle Order Entry data manipulation in Internal Operations

CVE-2026-60847 · Severity: low · CVSS 3.4 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability in the Internal Operations component of Oracle Order Entry could allow a high-privileged user with access to the underlying server to modify or delete business data. Oracle Order Entry is part of the E-Business Suite used by organizations to manage customer orders and fulfillment. While the risk is limited to users who already have significant administrative access, an exploit could lead to data inaccuracies or a partial disruption of order processing services.

Technical details

This vulnerability affects the Internal Operations component of Oracle Order Entry within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a local exploit, requiring the attacker to have existing logon access to the infrastructure where the software executes. The attacker must also possess high privileges (PR:H). Successful exploitation allows the attacker to perform unauthorized updates, insertions, or deletions of data accessible to the Order Entry product, and can result in a partial denial of service (DoS). The vulnerability does not appear to impact data confidentiality. Fixes are typically delivered via Oracle's Critical Patch Update (CPU) program.

Affected products

  • Oracle Order Entry (E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References