Description
Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation enabling full control over Applications DBA
Action: Patch or Mitigate
AI Analysis

Impact

The vulnerability resides in the ADPatch component of Oracle’s Applications DBA in Oracle E‑Business Suite. An attacker who gains local logon to the infrastructure where Applications DBA runs can exploit this flaw, requiring only a second human’s interaction to achieve full compromise. The impact includes loss of confidentiality, integrity, and availability—effectively a takeover of the applications database service. The weakness is documented by CVSS‑3.1 as AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, with a Base score of 7.8.

Affected Systems

Oracle Corporation’s Applications DBA product for Oracle E‑Business Suite, specifically the ADPatch component, in supported versions 12.2.3 through 12.2.15. Users operating any of these releases are affected by the flaw.

Risk and Exploitability

The CVSS severity is high (score 7.8) but the EPSS indicates < 1 % likely to see automated exploitation, and the vulnerability is not catalogued in the CISA KEV list. The flaw requires the attacker to have local access to the host and to rely on a third party to trigger the exploit, which limits but does not eliminate the threat, especially for environments with insufficient access controls or inadequate monitoring of administrative activity.

Generated by OpenCVE AI on September 17, 2026 at 02:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult Oracle Security Alerts for an official patch or upgrade for the ADPatch component in affected Applications DBA versions 12.2.3‑12.2.15
  • Restrict local logon rights to the hosts running Applications DBA to authorized personnel only and enforce least privilege on OS accounts used by Applications DBA processes
  • Segregate the network: isolate Applications DBA servers behind firewalls and adopt strict segmentation to limit lateral movement
  • Monitor system logs for anomalous activity related to Applications DBA processes, including unexpected logins and administrative commands

Generated by OpenCVE AI on September 17, 2026 at 02:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Applications DBA via ADPatch
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Dba
CPEs cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Dba
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Dba
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:40.885Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83159

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:26.783

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T02:15:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control