Description
Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology Stack. Successful attacks of this vulnerability can result in takeover of Oracle Applications Technology Stack. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists in the Client System Analyzer component of Oracle Applications Technology Stack. A remote attacker who can access the system over HTTP can exploit a flaw that does not require any credentials. Upon successful exploitation the attacker can take full control of the stack, gaining confidentiality, integrity, and availability impacts across the affected environment.

Affected Systems

The impact applies to Oracle Corporate products, specifically the Oracle Applications Technology Stack component known as Client System Analyzer. Versions 12.2.3 through 12.2.15 are vulnerable. No other product or version is listed as affected.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 reflects is network based (HTTP) and does not necessitate user interaction, implying that a remote attacker could execute this with minimal effort. Exploit probability is indicated by the EPSS score of less than 1%, suggesting that while the vulnerability is high risk, it is unlikely to be widely seen in the wild at present. The vulnerability is not recorded in the CISA KEV catalog, which aligns with the low EPSS score. Attackers would likely require knowledge of the specific HTTP endpoint that hosts the Client System Analyzer component, but the absence.

Generated by OpenCVE AI on August 2, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s released security update for Oracle Applications Technology Stack 12.2.3‑12.2.15 as provided in the July 2026 CPU. This patch eliminates the flaw that allows unauthenticated exploitation.
  • Restrict network exposure of the Client System Analyzer component by limiting HTTP rule that blocks all inbound HTTP traffic except from authorized management devices. This reduces the attack surface regardless of whether the patch has been applied.
  • Verify that the authentication mechanisms for the Component Analyzer are enabled and properly configured, ensuring that no default or weak credentials remain on the installation.

Generated by OpenCVE AI on August 2, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Client System Analyzer Remote Exploit Enables Full Stack Compromise

Sun, 26 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Client System Analyzer Remote Exploit Enables Full Stack Compromise

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology Stack. Successful attacks of this vulnerability can result in takeover of Oracle Applications Technology Stack. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Technology Stack
CPEs cpe:2.3:a:oracle:applications_technology_stack:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Technology Stack
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Technology Stack
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:27:10.169Z

Reserved: 2026-07-08T15:51:55.576Z

Link: CVE-2026-60670

cve-icon Vulnrichment

Updated: 2026-07-24T19:27:04.860Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:07.980

Modified: 2026-08-07T21:03:43.240

Link: CVE-2026-60670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function