Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Attachments / File Upload component of Oracle Application Object Library in Oracle E‑Business Suite. An attacker with only low privileges and network access to the HTTP interface can upload malicious files that are then executed with the privileges of the library service, allowing the attacker to fully compromise the application, jeopardizing confidentiality, integrity, and availability of the system.

Affected Systems

Oracle Corporation’s Oracle Application Object Library product, versions 12.2.3 through 12.2.15, is affected.

Risk and Exploitability

The flaw has a CVSS 3.1 base score of 8.8, indicating high severity, while the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation probability. The attack vector is through a standard HTTP request and requires only low privileged access with no user interaction; successful exploitation would grant the attacker full control of the library.

Generated by OpenCVE AI on September 20, 2026 at 09:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch that addresses the file upload vulnerability in the Oracle Application Object Library.
  • Configure network firewalls or web application filters to restrict HTTP access to the Attachments component only to privileged users.
  • Disable the upload feature if it is not required in your deployment.

Generated by OpenCVE AI on September 20, 2026 at 09:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege File Upload Exploit in Oracle Application Object Library

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Attachment Upload in Oracle Application Object Library
Weaknesses CWE-434

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Attachment Upload in Oracle Application Object Library
Weaknesses CWE-284
CWE-434

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:16:47.073Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83163

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:34.429Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:27.230

Modified: 2026-09-17T16:18:06.717

Link: CVE-2026-83163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:30:18Z

Weaknesses