Description
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw within the Oracle Applications DBA component of Oracle E‑Business Suite’s Internal Operations allows an attacker who already possesses high‑level privileges to remotely access the DBA service over HTTP and seize control of the process. The vulnerability stems from improper privilege checks and is identified as CWE‑269 (Improper Privilege Management). Successful exploitation can result in complete takeover of the DBA, granting the attacker the same high‑privilege level as the affected user, thereby enabling read, write, or delete operations on sensitive configuration and business data, as well as the potential to disrupt related services.

Affected Systems

The vulnerability affects Oracle Applications DBA versions 12.2.3 through 12.2.15 in Oracle E‑Business Suite, released by Oracle Corporation. The relevant product component is Internal Operations within the DBA service.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 indicates a moderate to high severity, with coupled impacts on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a relatively low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be able to reach the HTTP endpoint from the network and already have high‑level credentials; once those prerequisites are satisfied, the flaw can be used to remotely compromise the DBA process without user interaction.

Generated by OpenCVE AI on August 2, 2026 at 19:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Oracle Applications DBA to remediate the privilege management flaw or upgrade to a supported version beyond 12.2.15.
  • Restrict HTTP access to the DBA endpoint by employing firewalls or network segmentation so that only authorized internal hosts can reach the service.
  • Enable detailed logging for all HTTP requests to the DBA service and regularly review logs for suspicious activity to detect attempted exploitation attempts.

Generated by OpenCVE AI on August 2, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Remote Compromise of Oracle Applications DBA via HTTP

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title High-Privilege Remote Compromise of Oracle Applications DBA via HTTP

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title High Privilege Compromise via HTTP in Oracle Applications DBA
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High Privilege Compromise via HTTP in Oracle Applications DBA
Weaknesses CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Dba
CPEs cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Dba
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Dba
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:51.956Z

Reserved: 2026-07-08T15:51:55.613Z

Link: CVE-2026-61107

cve-icon Vulnrichment

Updated: 2026-07-23T19:29:17.302Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management