Description
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Applications DBA executes to compromise Oracle Applications DBA. While the vulnerability is in Oracle Applications DBA, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle Applications DBA internal operations component of Oracle E‑Business Suite, due to improper access control (CWE-284), allows a local attacker with low‑privileged access to the infrastructure where the DBA runs to compromise the DBA, potentially exposing all data that the DBA can access. The attack is deemed easily exploitable, with a CVSS v3.1 base score of 6.5 that affects confidentiality only.

Affected Systems

affected product is Oracle Applications DBA, part of Oracle E‑Business Suite, with versions 12.2.3 through 12.2.15 vulnerable. Systems running any of these releases and where the DBA is deployed locally are at risk, and the vulnerability can impact additional Oracle products due to the described scope change.

Risk and Exploitability

With a local attack vector, low attack complexity, and low privilege requirements, the EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog. However, because the exploit changes the security scope, an attacker who succeeds can reach higher‑level data or additional components. The CVSS score of 6.5 indicates moderate severity, but the potential for widespread data exposure warrants immediate attention.

Generated by OpenCVE AI on August 2, 2026 at 21:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch bundle released in the Oracle Computer Update for July 2026 that fixes Oracle Applications DBA
  • Restrict local system access by limiting logon privileges for users who can reach the infrastructure hosting the DBA
  • Reconfigure Oracle Applications DBA to run with the minimum required permissions and disable any local execution paths that are not essential

Generated by OpenCVE AI on August 2, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Applications DBA via Improper Access Control

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low Privilege Escalation in Oracle Applications DBA Enabling Unauthorized Data Access
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Escalation in Oracle Applications DBA Enabling Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Applications DBA executes to compromise Oracle Applications DBA. While the vulnerability is in Oracle Applications DBA, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle applications Dba
CPEs cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Dba
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Applications Dba
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-05T13:46:57.367Z

Reserved: 2026-07-08T15:51:55.588Z

Link: CVE-2026-60761

cve-icon Vulnrichment

Updated: 2026-07-24T15:15:12.932Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:15.493

Modified: 2026-08-05T15:16:56.583

Link: CVE-2026-60761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses