Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle Application Object Library component of Oracle E‑Business Suite and is an authorization flaw (CWE‑284). It permits a low‑privileged attacker who can reach the service over HTTP to compromise the application and ultimately take it over. Successful exploitation would compromise confidentiality, integrity, and availability, allowing the attacker to control the application and potentially access sensitive data.

Affected Systems

Affected versions of the Oracle Application Object Library are 12.2.3 through 12.2.15. The vulnerability applies to the Core component of the product.

Risk and Exploitability

The CVSS 3.1 Base Score of 7.5 indicates a high severity attack that could fully compromise the system. The EPSS score of less than 1% suggests that the exploitation rate is currently low, but the lack of listing in the CISA KEV catalog does not mitigate the risk of a targeted breach. Attackers would need network access to the HTTP interface and low privilege credentials to launch the exploit, after which the application can be fully taken over.

Generated by OpenCVE AI on August 4, 2026 at 02:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch for Application Object Library 12.2.15 or later, following the CPU guidance from Oracle.
  • Restrict HTTP access to the Application Object Library by limiting connections to trusted internal hosts through firewalls or network segmentation.
  • Monitor the application and audit logs for anomalous activity and review access rights regularly to detect potential exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Takeover of Oracle Application Object Library

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Low‑privilege Remote Exploitation of Oracle Application Object Library Leading to Full Compromise

Sun, 26 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low‑privilege Remote Exploitation of Oracle Application Object Library Leading to Full Compromise
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:21:54.902Z

Reserved: 2026-07-08T15:51:55.589Z

Link: CVE-2026-60770

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:23.141Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:16.067

Modified: 2026-07-30T17:37:02.933

Link: CVE-2026-60770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses