Description
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Applications Manager executes to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the RapidClone command‑line component of Oracle Applications Manager allows an attacker with local infrastructure access to compromise the Application Manager. The vulnerability can lead to a complete takeover of the application, impacting confidentiality, integrity, and availability.

Affected Systems

Oracle Corporation’s Oracle Applications Manager, a component of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 contain the RapidClone flaw. These are the only installed releases documented as impacted by the advisory.

Risk and Exploitability

The attacker must have local host access to the infrastructure where Oracle Applications Manager runs. Once that foothold is achieved, the exploit permits takeover of the Application Manager. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Nonetheless, the high CVSS base score of 8.4 and the ability to take over the application make this a significant risk that can only be mitigated by patching or disabling the vulnerable interface.

Generated by OpenCVE AI on August 13, 2026 at 11:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch released in Oracle’s July 2026 CPU update for Oracle Applications Manager
  • If patching cannot occur immediately, restrict file system permissions on the RapidClone executable directory to the minimal necessary users to prevent unauthorized execution
  • If RapidClone usage is unnecessary, disable the command‑line interface in the Application Manager configuration settings
  • If patching cannot occur, monitor the system for unauthorized use of the RapidClone component

Generated by OpenCVE AI on August 13, 2026 at 11:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title RapidClone Command‑Line Exploit in Oracle Applications Manager Allows Full Compromise

Wed, 12 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Command-Line Exploit Enables Full Application Takeover
Weaknesses CWE-285
CWE-94

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Command-Line Exploit Enables Full Application Takeover
Weaknesses CWE-285
CWE-94

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Command‑Line RapidClone Vulnerability Enabling Local Privilege Escalation and Takeover in Oracle Applications Manager
Weaknesses CWE-272
CWE-284

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Command‑Line RapidClone Vulnerability Enabling Local Privilege Escalation and Takeover in Oracle Applications Manager
Weaknesses CWE-272
CWE-284

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Command-Line Exploit Allows Takeover of Oracle Applications Manager
Weaknesses CWE-269
CWE-284

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Command-Line Exploit Allows Takeover of Oracle Applications Manager
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Applications Manager executes to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Manager
CPEs cpe:2.3:a:oracle:applications_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Manager
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:22:18.143Z

Reserved: 2026-07-08T15:51:55.588Z

Link: CVE-2026-60763

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:15.720

Modified: 2026-08-06T15:29:41.170

Link: CVE-2026-60763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T12:00:05Z

Weaknesses