Description
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the ADPatch component of the Oracle Applications DBA product, part of Oracle E‑Business Suite. It allows a low‑privileged attacker with network access via HTTP to gain full control of the database administration interface. The flaw results in confidentiality, integrity, and availability impacts, with a CVSS 3.1 base score of 8.8 indicating a high‑severity threat.

Affected Systems

Oracle Applications DBA versions 12.2.3 through 12.2.15 are affected. Users running any of these releases that expose the HTTP interface to the network must verify whether they have applied the July 2026 CPU patch. The affected product is the Oracle Applications DBA component ADPatch within the Oracle E‑Business Suite.

Risk and Exploitability

The high CVSS score of 8.8 reflects the potential for complete takeover, while the EPSS score of less than 1 % suggests that observed exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, requiring only network connectivity to the vulnerable HTTP endpoint and no elevated privileges, making it potentially exploitable by unauthenticated or low‑privileged users.

Generated by OpenCVE AI on August 2, 2026 at 19:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle E‑Business Suite July 2026 CPU patch that addresses the ADPatch vulnerability
  • Restrict network access to the Oracle Applications DBA HTTP interface using firewall rules or access‑control lists to limit connections to trusted systems
  • Enforce strict least‑privilege controls on all accounts that access the Oracle Applications DBA interface and audit any accounts with elevated rights
  • Monitor authentication and session activity for anomalous behavior on the Oracle Applications DBA system

Generated by OpenCVE AI on August 2, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Oracle Applications DBA ADPatch Privilege Escalation via HTTP

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Oracle Applications DBA ADPatch Privilege Escalation via HTTP
Weaknesses CWE-284

Mon, 27 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Enables Full Compromise of Oracle Applications DBA

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Enables Full Compromise of Oracle Applications DBA
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Dba
CPEs cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Dba
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Dba
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:53.043Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61110

cve-icon Vulnrichment

Updated: 2026-07-23T19:31:30.426Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function