Description
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Takeover
Action: Patch
AI Analysis

Impact

A vulnerability in Oracle Mobile Application Server, specifically the MWA Terminal Server component, allows an unauthenticated attacker with network access over TCP to compromise the server. Successful exploitation can lead to a full takeover of the application server, impacting confidentiality, integrity, and availability. The weakness demonstrates improper access control and potential information exposure, as reflected in the associated CWEs.

Affected Systems

The affected systems are Oracle Mobile Application Server products from Oracle Corporation, with supported versions from 12.2.3 through 12.2.15.

Risk and Exploitability

With a CVSS v3.1 base score of 8.1, the vulnerability is considered high severity. However, the EPSS score of less than 1% indicates a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers only need unauthenticated network connectivity on TCP to leverage the flaw, so restricting or monitoring this access remains an important protective measure.

Generated by OpenCVE AI on September 20, 2026 at 07:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Mobile Application Server patch or upgrade to a fixed release.
  • Restrict inbound TCP access to the MWA Terminal Server by configuring firewall rules that allow only trusted hosts.
  • Disable unnecessary services and interfaces on the Oracle Mobile Application Server to reduce the attack surface.
  • Monitor system logs for unexpected authentication attempts or configuration changes related to the MWA Terminal Server.

Generated by OpenCVE AI on September 20, 2026 at 07:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via TCP in Oracle Mobile Application Server

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Attacker Can Compromise Oracle Mobile Application Server via TCP
Weaknesses CWE-200
CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Attacker Can Compromise Oracle Mobile Application Server via TCP
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle mobile Application Server
CPEs cpe:2.3:a:oracle:mobile_application_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mobile Application Server
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Mobile Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:23.061Z

Reserved: 2026-08-31T15:40:57.360Z

Link: CVE-2026-83464

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:18.317Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:55.250

Modified: 2026-09-17T14:17:44.870

Link: CVE-2026-83464

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management