Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Application Object Library component, the AOL Generic Loader, allows an attacker who has already logged on to the infrastructure where this library executes to fully compromise it. The vulnerability results in confidentiality, integrity and availability impacts, as an attacker could effectively take control of the library. The CVSS 3.1 base score of 6.7 reflects a medium‑to‑high severity with local access and high privilege requirements.

Affected Systems

Oracle Corporation’s Oracle Application Object Library, part of the Oracle E‑Business Suite, is affected. Affected versions are 12.2.3 through 12.2.15. The vulnerability specifically involves the AOL Generic Loader component of the library.

Risk and Exploitability

The CVSS score of 6.7 indicates a moderate‑to‑high risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a high‑privileged user who has access to the host infrastructure, implying that the attack vector is local, with high privileges. Successful exploitation could lead to a takeover of the Oracle Application Object Library and the data it manages.

Generated by OpenCVE AI on August 5, 2026 at 02:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Application Object Library patch provided in the July 2026 security update.
  • Restrict physical and network access to the servers running the library to only trusted administrators.
  • Limit or disable the AOL Generic Loader functionality if it is unnecessary for business operations.

Generated by OpenCVE AI on August 5, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Risk in Oracle Application Object Library

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Full Control of Oracle Application Object Library
Weaknesses CWE-269

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Full Control of Oracle Application Object Library
Weaknesses CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Local Takeover via AOL Generic Loader in Oracle Application Object Library
Weaknesses CWE-269
CWE-284

Mon, 27 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title High-Privilege Local Takeover via AOL Generic Loader in Oracle Application Object Library
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:38.435Z

Reserved: 2026-07-08T15:51:55.589Z

Link: CVE-2026-60776

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:16.098Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:16.800

Modified: 2026-08-01T05:17:00.923

Link: CVE-2026-60776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:30:03Z

Weaknesses