Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Takeover of Oracle Application Object Library
Action: Immediate Patch
AI Analysis

Impact

A difficult to exploit flaw in Oracle Application Object Library allows a high‑privilege attacker with network access over HTTP to compromise the library, potentially enabling full takeover. The vulnerability is classified with CVSS Base Score 8.0 and affects confidentiality, integrity, and availability. Attackers could further impact other E‑Business Suite components because the vulnerability’s scope is changeable.

Affected Systems

The affected product is Oracle Application Object Library in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, within the Core component.

Risk and Exploitability

The CVSS score of 8.0 indicates high severity, but the EPSS score is less than 1% and the issue is not in the CISA KEV catalog, implying low current exploitation prevalence. Exploitation requires a high‑privilege account with network access to the HTTP interface, making it realistic in environments where such privileges exist. Because the flaw can affect additional products, the overall impact is potentially broader than the library alone.

Generated by OpenCVE AI on September 18, 2026 at 19:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle update that fixes the Oracle Application Object Library vulnerability.
  • Revoke or limit high‑privilege permissions for HTTP service users to enforce least privilege.
  • Segment network access to the HTTP service using firewall rules and monitor for suspicious activity.

Generated by OpenCVE AI on September 18, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title High Privilege Compromise of Oracle Application Object Library via HTTP Exploit

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title High Privilege Compromise of Oracle Application Object Library via HTTP Exploit
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:16:15.321Z

Reserved: 2026-08-31T15:40:57.344Z

Link: CVE-2026-83178

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:31.096Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:28.910

Modified: 2026-09-17T16:18:07.303

Link: CVE-2026-83178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:15:14Z

Weaknesses