Description
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Search Bean component of Oracle Applications Framework within Oracle E‑Business Suite and is classified as an improper access control flaw. It allows an attacker with low‑privileged access over HTTP to compromise the framework, resulting in loss of confidentiality, integrity, and availability for the application.

Affected Systems

Oracle Applications Framework for Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score of less than 1% suggests that exploitation is unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based via HTTP and requires only low‑privileged access to the application; successful exploitation gives the attacker complete control of the Oracle Applications Framework.

Generated by OpenCVE AI on August 4, 2026 at 03:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch for Oracle Applications Framework
  • Restrict HTTP access to Oracle Applications Framework to trusted internal networks only
  • Disable or restrict the Search Bean functionality for non‑administrative users

Generated by OpenCVE AI on August 4, 2026 at 03:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Oracle Applications Framework Search Bean Improper Access Control Leading to Remote Takeover

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Oracle Applications Framework Search Bean Improper Access Control Leading to Remote Takeover

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Exploitation Allows Takeover of Oracle Applications Framework

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Exploitation Allows Takeover of Oracle Applications Framework
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Framework
CPEs cpe:2.3:a:oracle:applications_framework:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Framework
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:19:57.729Z

Reserved: 2026-07-08T15:51:55.577Z

Link: CVE-2026-60675

cve-icon Vulnrichment

Updated: 2026-07-24T19:19:53.779Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:08.453

Modified: 2026-07-31T21:23:28.820

Link: CVE-2026-60675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses