Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspusep2026.html |
|
History
Thu, 17 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High‑Privilege Takeover via HTTP in Oracle Applications DBA | |
| Weaknesses | CWE-264 CWE-284 |
Tue, 15 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle applications Dba |
|
| CPEs | cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle applications Dba |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-09-15T20:03:27.577Z
Reserved: 2026-08-31T15:40:57.341Z
Link: CVE-2026-83117
No data.
Status : Deferred
Published: 2026-09-15T20:18:22.043
Modified: 2026-09-16T19:36:43.087
Link: CVE-2026-83117
No data.
OpenCVE Enrichment
Updated: 2026-09-17T02:15:08Z