CVE-2026-60842
Analyzed Analyzed - Analysis Complete

Cross-Site Scripting in Oracle Knowledge Management

Vulnerability report for CVE-2026-60842, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-08-10

Assigner: Oracle

Description

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Knowledge Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Knowledge Management accessible data as well as unauthorized read access to a subset of Oracle Knowledge Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oracle knowledge_management From 12.2.5 (inc) to 12.2.15 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle Knowledge Management within Oracle E-Business Suite. It allows an unauthenticated attacker to remotely access the system via HTTP and potentially compromise it. The attack requires user interaction and could impact other connected products. The vulnerability enables unauthorized data access and modifications.

Detection Guidance

Detection requires checking for Oracle Knowledge Management versions 12.2.5-12.2.15. Inspect Oracle E-Business Suite components via administrative interfaces or logs for unusual search-related activity. No specific commands are provided in the CVE details.

Impact Analysis

An attacker could exploit this to read or modify some data in Oracle Knowledge Management without authentication. This may lead to data breaches, unauthorized changes, or further attacks on connected systems. User interaction is required, meaning a victim must perform an action for the exploit to succeed.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR (data protection) and HIPAA (health data security) requirements. Organizations using affected Oracle E-Business Suite versions may face compliance violations, legal penalties, or reputational damage due to potential data breaches.

Mitigation Strategies

Apply Oracle's official security patches for Oracle Knowledge Management immediately. If patches are unavailable, restrict network access to the affected component via firewalls or disable HTTP access to Oracle Knowledge Management until updates are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-60842. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart