Junglewise Threat Intelligence

CVE-2026-60959: Oracle E-Business Suite data compromise in SDP Number Portability

CVE-2026-60959 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle SDP Number Portability. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle SDP Number Portability component of the Oracle E-Business Suite, which manages telecommunications number portability operations. An attacker with basic user credentials can gain unauthorized access to sensitive data or modify critical information within the system. This could lead to significant data breaches or the corruption of essential business records.

Technical details

This vulnerability affects the Internal Operations component of Oracle SDP Number Portability within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can exploit this to achieve high confidentiality and integrity impacts, potentially resulting in the unauthorized creation, deletion, or modification of all accessible data within the component. The vulnerability does not impact system availability (A:N) or require user interaction. Patches are typically released via the Oracle Critical Patch Update (CPU) program.

Affected products

  • Oracle Corporation SDP Number Portability 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats