Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle User Management accessible data as well as unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpuapr2026.html |
|
History
Wed, 22 Apr 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle User Management Unauthorized Data Modification via Workflow Events | |
| Weaknesses | CWE-284 |
Wed, 22 Apr 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle User Management Privilege Escalation via Workflow and Business Events | Oracle User Management Unauthorized Data Modification via Workflow Events |
| Weaknesses | CWE-284 |
Wed, 22 Apr 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle User Management Privilege Escalation via Workflow and Business Events | |
| Weaknesses | CWE-284 |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle User Management accessible data as well as unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). | |
| First Time appeared |
Oracle
Oracle user Management |
|
| CPEs | cpe:2.3:a:oracle:user_management:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle user Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-04-21T20:35:09.266Z
Reserved: 2026-01-05T18:07:34.727Z
Link: CVE-2026-22014
No data.
Status : Received
Published: 2026-04-21T21:16:28.140
Modified: 2026-04-21T21:16:28.140
Link: CVE-2026-22014
No data.
OpenCVE Enrichment
Updated: 2026-04-22T07:15:11Z