Description
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: JRI and other Java utils). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Applications DBA, a component of Oracle E-Business Suite, contains a difficult-to-exploit flaw in its JRI and Java utilities that allows an unauthenticated attacker who can reach the service over HTTP to compromise the application. The vulnerability is a weakness in authentication (CWE-284) that, if successfully triggered, can lead to full takeover of the Oracle Applications DBA, affecting confidentiality, integrity, and availability. The flaw requires the presence of a human user to interact with the attacker’s request; the attacker cannot complete the exploit without that user involvement.

Affected Systems

Oracle Corporation’s Oracle Applications DBA (Oracle E‑Business Suite) versions 12.2.3 through 12.2.15 are affected. The issue is present in the JRI and other Java utility components of the product and is applicable to all installations that expose the HTTP interface without proper authentication.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 indicates a high‑impact vulnerability. The vector specifies that the attack requires network access over HTTP (AV:N), has a high attack complexity (AC:H), no privileges (PR:N), and user interaction (UI:R), indicating that while the flaw is serious, it is not easily exploitable by an automated attacker. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, yet the potential for a complete application takeover warrants prompt action.

Generated by OpenCVE AI on August 26, 2026 at 03:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that eliminates the flaw or upgrade to Oracle Applications DBA version 12.2.16 or later.
  • If a patch is not yet available, configure the network to restrict HTTP/HTTPS access to Oracle Applications DBA to trusted internal addresses or VPN endpoints.
  • If the JRI and Java utilities are not required for business processes, disable or remove those components from the deployment.
  • Enable detailed logging for HTTP requests and monitor logs for suspicious activity that may indicate attempts to exploit the vulnerability.

Generated by OpenCVE AI on August 26, 2026 at 03:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in Oracle Applications DBA Allows Full Compromise

Tue, 25 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Leading to Oracle Applications DBA Compromise
Weaknesses CWE-264
CWE-287

Tue, 25 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Leading to Oracle Applications DBA Compromise
Weaknesses CWE-264
CWE-287

Fri, 21 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Applications DBA Allows Full System Compromise
Weaknesses CWE-284

Wed, 19 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Applications DBA Allows Full System Compromise
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: JRI and other Java utils). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Dba
CPEs cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Dba
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Dba
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T03:56:18.719Z

Reserved: 2026-08-04T22:06:34.589Z

Link: CVE-2026-70681

cve-icon Vulnrichment

Updated: 2026-08-25T16:20:30.425Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:19.953

Modified: 2026-08-31T15:07:35.020

Link: CVE-2026-70681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:00:04Z

Weaknesses