Description
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Applications DBA. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Internal Operations component of Oracle Applications DBA, where an attacker with low privileges who can reach the system over HTTP may exploit a flaw that allows them to bypass normal access controls. As a result the attacker can read or modify sensitive database information and can trigger a partial denial of service. The weakness results in a confidentiality impact rated high and a partial availability impact.

Affected Systems

Oracle Corporation’s Oracle Applications DBA product in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 reflects the severity of the flaw. Exploitation is considered easy with available network access via HTTP and does not require elevated privileges. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Attackers can gain unauthorized read or write access to all data exposed by the DBA component and can produce a measurable impact on availability by disrupting service availability. The attack requires only network connectivity and low user privileges, making the risk significant for organizations that expose the DBA interface to untrusted networks.

Generated by OpenCVE AI on August 19, 2026 at 12:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle security alerts or contact Oracle support for patch or update information.
  • Restrict network access to the Oracle Applications DBA HTTP endpoint using firewall rules or VLAN segmentation so that only trusted hosts can reach it.
  • Configure the Internal Operations services to require strong authentication and enforce least privilege access controls.

Generated by OpenCVE AI on August 19, 2026 at 12:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote HTTP Vulnerability in Oracle Applications DBA
Weaknesses CWE-280
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Applications DBA. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle applications Dba
CPEs cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Dba
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Applications Dba
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:14.151Z

Reserved: 2026-08-04T22:06:34.589Z

Link: CVE-2026-70680

cve-icon Vulnrichment

Updated: 2026-08-19T12:11:51.199Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:19.833

Modified: 2026-08-31T15:07:39.677

Link: CVE-2026-70680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T12:15:03Z

Weaknesses
  • CWE-280

    Improper Handling of Insufficient Permissions or Privileges

  • CWE-284

    Improper Access Control