Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Core component of Oracle Application Object Library, part of Oracle E‑Business Suite. A local user who can log into the host with low privileges can compromise the library and gain unauthorized access to the data it stores or processes. The attack does not require user interaction, and the impact is a full confidentiality breach of all library data. The vulnerability is an improper authorization flaw that can also extend its reach to other Oracle products sharing the same environment, due to a scope‑changing condition.

Affected Systems

Oracle Corporation’s Application Object Library in Oracle E‑Business Suite is affected for versions 12.2.3 through 12.2.15, specifically the Core component.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates a moderate severity risk. The EPSS score of less than 1% shows that the likelihood of real‑world exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access to the infrastructure where the library runs and a low‑privileged user account; once exploited, confidentiality is fully compromised, and the scope change may affect other Oracle products sharing the environment.

Generated by OpenCVE AI on August 2, 2026 at 19:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch released for the Application Object Library, or upgrade to a version earlier than 12.2.3 or later than 12.2.15 that contains the fix.
  • If a patch or upgrade is not immediately available, restrict local user accounts from interacting with the Oracle Application Object Library process and enforce strict least‑privilege policies on the host.
  • Limit unprivileged users’ access to internal services that communicate with the library and apply the most restrictive access controls possible.
  • Monitor audit logs for anomalous access to the library’s data and configure alerts for suspicious activity.

Generated by OpenCVE AI on August 2, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Authorization Bypass Leading to Data Disclosure in Oracle Application Object Library

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Authorization Bypass Leading to Data Disclosure in Oracle Application Object Library

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unprivileged Local Access Leads to Data Disclosure in Oracle Application Object Library
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unprivileged Local Access Leads to Data Disclosure in Oracle Application Object Library
Weaknesses CWE-284
CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-05T13:47:29.172Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61111

cve-icon Vulnrichment

Updated: 2026-07-23T19:27:51.264Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:00:12Z

Weaknesses