{"cve":"CVE-2026-83117","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[12.2.3,12.2.15]"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Applications DBA","source":"cna","vendor":"Oracle Corporation"},"product":"applications_dba","vendor":"oracle"}],"created":"2026-09-16T02:30:07.503554+00:00","title":"High-Privilege Remote Takeover of Oracle Applications DBA via HTTP","updated":"2026-09-20T10:15:05.111756+00:00","vendors":["oracle","oracle$PRODUCT$applications_dba"]},"epss":{"score":0.0043},"mitre":{"cpes":["cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*"],"created":"2026-09-15T20:03:27.577000+00:00","description":"Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA.  Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.2,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/83xxx/CVE-2026-83117.json","references":["https://www.oracle.com/security-alerts/cspusep2026.html"],"title":null,"updated":"2026-09-17T13:10:44.227000+00:00","vendors":["oracle","oracle$PRODUCT$applications_dba"],"weaknesses":[]},"nvd":{"cpes":[],"created":"2026-09-15T20:18:22.043000+00:00","description":"Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA.  Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.2,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-83117.json","references":["https://www.oracle.com/security-alerts/cspusep2026.html"],"title":null,"updated":"2026-09-17T14:17:33.890000+00:00","vendors":[],"weaknesses":["CWE-269"]},"opencve":{"changes":[{"created":"2026-09-15T20:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA.  Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$applications_dba"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$applications_dba"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspusep2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":7.2,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"6be236c9-8775-4489-ba8b-0712cc725d9e"},{"created":"2026-09-17T02:30:00+00:00","data":[{"details":{"new":"High‑Privilege Takeover via HTTP in Oracle Applications DBA","old":null},"type":"title"},{"details":{"added":["CWE-264","CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"49289f26-f844-4dee-9cde-0a422c254c05"},{"created":"2026-09-17T14:30:00+00:00","data":[{"details":{"added":["CWE-269"],"removed":[]},"type":"weaknesses"},{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"1445080b-bd01-4446-b4d4-3942928011e0"},{"created":"2026-09-18T21:30:00+00:00","data":[{"details":{"new":null,"old":"High‑Privilege Takeover via HTTP in Oracle Applications DBA"},"type":"title"},{"details":{"added":[],"removed":["CWE-264","CWE-284"]},"type":"weaknesses"}],"id":"b2c0d8fd-5712-4650-ac33-3494af1fceb1"},{"created":"2026-09-20T10:30:00+00:00","data":[{"details":{"new":"High-Privilege Remote Takeover of Oracle Applications DBA via HTTP","old":null},"type":"title"}],"id":"ce9c10e7-3cbe-4d6a-bd98-f9cf1a3cd3ac"}],"cpes":{"data":["cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2026-09-15T20:03:27.577000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA.  Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":7.2,"vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.0043},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspusep2026.html"],"providers":["mitre","nvd"]},"title":{"data":"High-Privilege Remote Takeover of Oracle Applications DBA via HTTP","provider":"enrichment"},"updated":{"data":"2026-09-20T10:15:05.111756+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$applications_dba"],"providers":["mitre","enrichment"]},"weaknesses":{"data":["CWE-269"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-09-15T20:03:27.577000+00:00","description":"Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA.  Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-09-17T13:02:25.487000+00:00","vendors":[],"vulnrichment_repo_path":"2026/83xxx/CVE-2026-83117.json","weaknesses":["CWE-269"]}}