Description
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Application Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the MWA Terminal Server component of Oracle Mobile Application Server. The flaw permits a low‑privileged attacker with network access via HTTP to gain unauthorized access to data stored by the server. The impact is confined to confidentiality, allowing the attacker to view or retrieve critical data that should be protected.

Affected Systems

Oracle Mobile Application Server (part of Oracle E‑Business Suite) versions ranging from 12.2.3 to 12.2.15 are affected. The Vulnerable component is the MWA Terminal Server exposed through HTTP endpoints.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates moderate severity with a confidentiality impact. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the CVSS vector (AV:N, AC:L, PR:L, UI:N, S:U, C:H) suggests the vulnerability is easily exploitable by an attacker who is already a low‑privileged user on the network. The weakness is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack can be executed over the network without additional authentication.

Generated by OpenCVE AI on August 25, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a version that includes the fix for the MWA Terminal Server vulnerability.
  • Restrict inbound HTTP traffic to Oracle Mobile Application Server by configuring firewalls to allow only trusted hosts.
  • Enforce strict authentication and role‑based access controls for the MWA Terminal Server to ensure only authorized users can access sensitive data.

Generated by OpenCVE AI on August 25, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access Vulnerability in Oracle Mobile Application Server via HTTP

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Exploit Compromises Oracle Mobile Application Server
Weaknesses CWE-200
CWE-285

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Exploit Compromises Oracle Mobile Application Server
Weaknesses CWE-200
CWE-285

Fri, 21 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Oracle Mobile Application Server HTTP Endpoint
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Oracle Mobile Application Server HTTP Endpoint
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Application Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle mobile Application Server
CPEs cpe:2.3:a:oracle:mobile_application_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mobile Application Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Mobile Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:10:30.349Z

Reserved: 2026-08-04T22:06:34.593Z

Link: CVE-2026-70732

cve-icon Vulnrichment

Updated: 2026-08-25T15:00:41.779Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:25.853

Modified: 2026-08-28T18:25:48.863

Link: CVE-2026-70732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:30:06Z

Weaknesses