Description
Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation allowing complete control of Applications DBA
Action: Patch or Mitigate
AI Analysis

Impact

The flaw resides in the ADPatch component of Oracle’s Applications DBA for Oracle E‑Business Suite. It is a CWE‑284 Weak Authentication or Authorization weakness that lets an attacker who can log onto the host where Applications DBA runs gain control of the service. Because the vulnerability requires the attacker to act locally, it cannot be exploited remotely, but it can result in full takeover of the database administration functions. The description indicates that a second person’s action is necessary to trigger the exploit; it can be inferred that a human with local access must perform a manual step to activate the vulnerability.

Affected Systems

Oracle Corporation’s Applications DBA product, specifically the ADPatch component, is affected in supported Oracle E‑Business Suite releases 12.2.3 through 12.2.15. Users running any of these versions are exposed to the flaw.

Risk and Exploitability

The CVSS 3.1 base score of 7.8 reflects a high severity local privilege escalation. The EPSS score is below 1 %, indicating a low probability of automated exploitation. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires local logon rights and a third‑party action to activate the flaw, the risk is moderated by the need for privileged access; however, any environment with insufficient local access controls remains vulnerable.

Generated by OpenCVE AI on September 20, 2026 at 10:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s patch for the ADPatch component in the affected Oracle E‑Business Suite releases (12.2.3‑12.2.15) as detailed in the Oracle Security Alert
  • Restrict local logon permissions on servers running Applications DBA to authorized personnel only and enforce least privilege for the OS accounts that run the service
  • Isolate Applications DBA servers behind firewalls and implement strict network segmentation to limit lateral movement

Generated by OpenCVE AI on September 20, 2026 at 10:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via ADPatch in Oracle Applications DBA

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Applications DBA via ADPatch
Weaknesses CWE-269

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Applications DBA via ADPatch
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Dba
CPEs cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Dba
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Dba
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:17:10.608Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83159

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:37.623Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:26.783

Modified: 2026-09-17T16:18:06.137

Link: CVE-2026-83159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:30:17Z

Weaknesses