Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Sun, 02 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High-Privilege Remote Compromise of Oracle Applications DBA via HTTP |
Thu, 30 Jul 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High-Privilege Remote Compromise of Oracle Applications DBA via HTTP |
Tue, 28 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High Privilege Compromise via HTTP in Oracle Applications DBA | |
| Weaknesses | CWE-284 |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High Privilege Compromise via HTTP in Oracle Applications DBA | |
| Weaknesses | CWE-269 CWE-284 |
|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle applications Dba |
|
| CPEs | cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle applications Dba |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:38:12.422Z
Updated: 2026-08-01T03:56:51.956Z
Reserved: 2026-07-08T15:51:55.613Z
Link: CVE-2026-61107
Updated: 2026-07-23T19:29:17.302Z
No data.
No data.