Description
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA General Bugs). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Oracle Mobile Application Server component MWA General Bugs. It exploits improper access control (CWE-284), allowing an attacker with network access through HTTP to gain high privileges and complete control over the server. The flaw leads to confidentiality, integrity, and availability violations, permitting the adversary to execute arbitrary code, alter data, and disrupt services. The CVSS vector reflects a high severity (7.2) due to the need for network access, low attack complexity, high privileges, and no user interaction.

Affected Systems

Oracle Mobile Application Server versions from 12.2.3 through 12.2.15 are impacted. The issue is specific to the MWA General Bugs component of Oracle E‑Business Suite.

Risk and Exploitability

The CVSS base score of 7.2 classifies the vulnerability as high, yet the EPSS score of less than 1% signals a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Attackers would need a network route to the server’s HTTP interface, making the exploit remote but confined to those who can reach that interface. Because high privileges are obtained, the potential damage to an organization is significant if an attacker gains this access.

Generated by OpenCVE AI on August 2, 2026 at 20:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Mobile Application Server patch or upgrade to a version newer than 12.2.15 to eliminate the flaw.
  • Limit HTTP access to the server to trusted IP addresses or subnet ranges to reduce exposure.
  • Continuously monitor application logs and traffic for signs of exploitation attempts and enforce the principle of least privilege for all user accounts.

Generated by OpenCVE AI on August 2, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Access Exploit in Oracle Mobile Application Server

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title High-Privilege Vulnerability in Oracle Mobile Application Server Allows Remote Compromise
Weaknesses CWE-285

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Vulnerability in Oracle Mobile Application Server Allows Remote Compromise
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA General Bugs). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mobile Application Server
CPEs cpe:2.3:a:oracle:mobile_application_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mobile Application Server
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Mobile Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:59:09.584Z

Reserved: 2026-07-08T15:51:55.595Z

Link: CVE-2026-60845

cve-icon Vulnrichment

Updated: 2026-07-24T17:59:06.119Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:22.307

Modified: 2026-07-24T19:17:09.267

Link: CVE-2026-60845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:00:06Z

Weaknesses