Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Attachments / File Upload component of the Oracle E‑Business Suite's Application Object Library exploit the component over HTTP to upload and execute code in the context of the Application Object Library. If successful, the attacker can take full control of the library, compromising confidentiality, integrity and availability of the system.

Affected Systems

Affected are Oracle Corporation's Oracle Application Object Library product, versions 12.2.3 through 12.2.15 of the Oracle E‑Business Suite. These releases are specified as at risk by Oracle.

Risk and Exploitability

The CVSS base score of 8.8 classifies the flaw as high severity. The EPSS score is below 1 % and the vulnerability is not currently listed in the CISA KEV catalog, indicating a low current exploitation probability. The attack vector is through a normal HTTP request and only requires low privileged access; no user interaction is needed. Successful exploitation can lead to a complete takeover of the library, making risk management critical.

Generated by OpenCVE AI on September 17, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle E‑Business Suite patch that closes the file upload vulnerability.
  • Configure network firewalls or web application filters to restrict HTTP access to the Attachments component only to privileged users.
  • Disable Upload feature if it is not needed in your environment.

Generated by OpenCVE AI on September 17, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Attachment Upload in Oracle Application Object Library
Weaknesses CWE-284
CWE-434

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:16:47.073Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83163

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:34.429Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:27.230

Modified: 2026-09-17T16:18:06.717

Link: CVE-2026-83163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T01:30:08Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-434

    Unrestricted Upload of File with Dangerous Type