Description
Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for Asia/Pacific. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials for Asia/Pacific accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials for Asia/Pacific accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financials for Asia/Pacific. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification, deletion, and partial denial of service
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the Internal Operations component of Oracle Financials for Asia/Pacific (Oracle E‑Business Suite) versions 12.2.8 through 12.2-15 and allows an attacker with network access via HTTP and low privileges to create, delete, or modify critical data and to partially disrupt service. This leads to confidentiality, integrity, and availability breaches as reflected by the CVSS 8.3 score.

Affected Systems

Affected systems include Oracle Financials for Asia/Pacific from Oracle, specifically versions 12.2.8 to 12.2.15 of the Oracle E‑Business Suite applied in Asia/Pacific regions.

Risk and Exploitability

The CVSS score of 8.3 coupled with an EPSS probability of below 1% indicates a high severity yet low likelihood of current exploitation. Based on the description, the likely attack vector is through HTTP requests, and the vulnerability can be leveraged over the network without requiring elevated credentials. This allows a low‑privileged attacker to bypass access controls. Although not yet listed in the CISA KEV catalog, the potential for unauthorized data manipulation requires immediate attention and monitoring.

Generated by OpenCVE AI on September 20, 2026 at 08:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or update for Oracle Financials for Asia/Pacific that addresses this vulnerability
  • Restrict HTTP exposure of the application by using firewall rules or VPN so that only trusted IP ranges can reach the Internal Operations interface
  • Enforce strict role‑based access controls within the application to address the access control weakness (CWE‑284) and audit all data modification actions, monitoring logs for any unauthorized activity

Generated by OpenCVE AI on September 20, 2026 at 08:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Attack Enables Unrestricted Data Modification in Oracle Financials

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Enables Data Modification and Partial Denial of Service in Oracle Financials for Asia/Pacific
Weaknesses CWE-284

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Enables Data Modification and Partial Denial of Service in Oracle Financials for Asia/Pacific
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for Asia/Pacific. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials for Asia/Pacific accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials for Asia/Pacific accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financials for Asia/Pacific. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle financials For Asia\/pacific
CPEs cpe:2.3:a:oracle:financials_for_asia\/pacific:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle financials For Asia\/pacific
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle Financials For Asia\/pacific
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:45.854Z

Reserved: 2026-09-08T21:49:12.396Z

Link: CVE-2026-87125

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:59.493

Modified: 2026-09-18T19:17:08.803

Link: CVE-2026-87125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:45:17Z

Weaknesses