Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/oracle/complex-maintenance-repair-and-overhaul

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-61138 is a high-severity vulnerability in Oracle Complex Maintenance, Repair and Overhaul (part of Oracle E-Business Suite, component Internal Operations) affecting versions 12.2.3 through 12.2.15. It allows an unauthenticated attacker with network access via HTTP to potentially gain unauthorized access to critical data and perform limited unauthorized modifications. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting high confidentiality impact and limited integrity impact. Exploitation is considered difficult due to the required conditions. No official patch or remediation level is explicitly stated in the vendor advisory, but Oracle recommends applying Critical Patch Updates promptly. There are no known exploits in the wild at this time.

Join the discussion

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Complex Maintenance, Repair and Overhaul accessible data as well as unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Join the discussion

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Common Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair and Overhaul accessible data as well as unauthorized read access to a subset of Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

Join the discussion

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Join the discussion

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Join the discussion

CVE-2026-46915 is a high-severity vulnerability in Oracle Complex Maintenance, Repair and Overhaul component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. It allows a low privileged attacker with network access via HTTP to potentially take over the affected product. The vulnerability has a CVSS 3.1 base score of 8.5, indicating high impact on confidentiality, integrity, and availability. Exploitation is difficult and requires high attack complexity, but successful exploitation can lead to full compromise of the product and may affect additional Oracle products. Oracle has published a Critical Security Patch Update advisory recommending prompt patching and mitigation. No specific patch version is stated in the provided data. Mitigations include applying the Critical Security Patch Update as soon as possible and blocking network protocols required by the attack if patching is delayed. Removing unnecessary privileges may also reduce risk but could impact functionality. No known exploits in the wild have been reported at this time.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:maven/oracle/complex-maintenance-repair-and-overhaul
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses