Description
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Applications Manager executes to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Applications Manager’s RapidClone command‑line component allows an unauthenticated attacker who has already logged onto the host to execute privileged commands, resulting in a complete takeover of the manager. This flaw delivers confidentiality, integrity, and availability compromise in a single exploit, as an attacker can read, modify, and disrupt Application Manager data and operations. The CVSS v3.1 vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H yields a high 8.4 base score, highlighting its severity.

Affected Systems

Vendor Oracle issues this flaw for the Oracle E‑Business Suite product Oracle Applications Manager, affecting versions 12.2.3 through 12.2.15 inclusive. These are the only documented deployments impacted by the RapidClone component vulnerability.

Risk and Exploitability

With an AV:L score, the attack requires the attacker to be present on the network and to be able to log onto the host where the manager runs. The current EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, once the prerequisite host access is achieved, the attacker can elevate privileges within the Oracle Applications Manager application, potentially bypassing all user controls. Because the vulnerability affects core command‑line functionality, patching is the only definitive mitigation.

Generated by OpenCVE AI on August 5, 2026 at 01:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch released in Oracle’s July 2026 CPU update for Oracle Applications Manager
  • If patching cannot be applied immediately, remove local group read/write permissions for the RapidClone directory to prevent unauthorized command execution
  • Disable or restrict the RapidClone command‑line interface in the configuration if the functionality is not required for business operations
  • Sanitize and validate all arguments passed to RapidClone to mitigate command injection

Generated by OpenCVE AI on August 5, 2026 at 01:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Command-Line Exploit Enables Full Application Takeover
Weaknesses CWE-285
CWE-94

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Command‑Line RapidClone Vulnerability Enabling Local Privilege Escalation and Takeover in Oracle Applications Manager
Weaknesses CWE-272
CWE-284

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Command‑Line RapidClone Vulnerability Enabling Local Privilege Escalation and Takeover in Oracle Applications Manager
Weaknesses CWE-272
CWE-284

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Command-Line Exploit Allows Takeover of Oracle Applications Manager
Weaknesses CWE-269
CWE-284

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Command-Line Exploit Allows Takeover of Oracle Applications Manager
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Applications Manager executes to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Manager
CPEs cpe:2.3:a:oracle:applications_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Manager
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:22:18.143Z

Reserved: 2026-07-08T15:51:55.588Z

Link: CVE-2026-60763

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:15.720

Modified: 2026-08-06T15:29:41.170

Link: CVE-2026-60763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-285

    Improper Authorization

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')