Description
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: JRI and other Java utils). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Applications DBA, including JRI and other Java utilities, contains a difficult‑to‑exploit vulnerability that permits an unauthenticated attacker with network connectivity over HTTP to compromise the system. Successful exploitation can lead to complete takeover of Oracle Applications DBA, affecting confidentiality, integrity, and availability of the application. The weakness corresponds to improper access control, enabling full privilege escalation without authentication.

Affected Systems

Oracle Corporation’s Oracle Applications DBA (Oracle E‑Business Suite) versions 12.2.3 through 12.2.15 are affected. The flaw resides in components JRI and Java utilities of the product.

Risk and Exploitability

The CVSS v3.1 score of 7.5 reflects a high‑impact flaw; the vector indicates that the vulnerability requires network access (HTTP), no privileges, but does require user interaction. While the EPSS score is not available, the lack of authentication combined with the potential for full takeover places this flaw at a high priority in terms of risk. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly confirmed exploits, yet the potential impact warrants swift mitigation.

Generated by OpenCVE AI on August 19, 2026 at 01:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that removes the vulnerability or upgrade to Oracle Applications DBA version 12.2.16 or later.
  • If an immediate patch is unavailable, restrict HTTP access to Oracle Applications DBA by allowing traffic only from trusted internal subnets or VPNs.
  • Disable or restrict JRI and Java utilities components if they are not essential to business processes.
  • Implement monitoring of logs for suspicious HTTP requests and abnormal activity to detect attempted exploitation.

Generated by OpenCVE AI on August 19, 2026 at 01:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Applications DBA Allows Full System Compromise
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: JRI and other Java utils). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Dba
CPEs cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Dba
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Dba
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:00:58.959Z

Reserved: 2026-08-04T22:06:34.589Z

Link: CVE-2026-70681

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:19.953

Modified: 2026-08-18T21:17:19.953

Link: CVE-2026-70681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T01:30:05Z

Weaknesses