Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Application Object Library allows an unauthenticated attacker with network access through HTTP to create, delete, or modify critical data, or to gain unauthorized access to all accessible data. This can lead to alteration or theft of sensitive information without requiring user interaction or elevated privileges, representing a significant breach of confidentiality and integrity. The weakness is classified as CWE‑284, an improper access control vulnerability.

Affected Systems

The affected products are Oracle Corporation’s Oracle Application Object Library component of Oracle E-Business Suite, versions 12.2.3 through 12.2.15. These versions are included in the Oracle Application Object Library product line and are reachable via standard HTTP interfaces.

Risk and Exploitability

The CVSS v3.1 base score of 7.4 indicates high severity with substantial confidentiality and integrity impacts. The EPSS score of less than 1% suggests that the likelihood of exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector requires only network access via HTTP and no authentication, making it theoretically possible to exploit remotely by sending crafted HTTP requests to the vulnerable component. In practice, the need for network reachability to the target suggests a moderate to low exploitation risk, though the potential damage is high.

Generated by OpenCVE AI on August 2, 2026 at 19:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s July 2026 CPU patch for Oracle Application Object Library to eliminate the unauthenticated HTTP access flaw.
  • Configure the web server and network settings so that the Application Object Library endpoints are protected by authentication and are only reachable from authorized management hosts, preventing unauthenticated traffic.
  • Implement logging and monitoring for abnormal data modification or unauthorized access attempts on the Oracle Application Object Library component, and investigate any incidents promptly.

Generated by OpenCVE AI on August 2, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Application Object Library

Mon, 27 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Tampering in Oracle Application Object Library
Weaknesses CWE-640

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Tampering in Oracle Application Object Library
Weaknesses CWE-640

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:40.654Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61113

cve-icon Vulnrichment

Updated: 2026-07-23T19:42:15.799Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:00:12Z

Weaknesses