cve-2026-83117
HIGH CVSS 7.2 opencve
Description
Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Timeline
- Published
- 2026-09-15 20:18 UTC
- Last Modified
- 2026-09-17
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
mitre | ||
| 3.1 | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
nvd | ||
| 3.1 | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
opencve |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2026-83117",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "[12.2.3,12.2.15]"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Applications DBA",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "applications_dba",
"vendor": "oracle"
}
],
"created": "2026-09-16T02:30:07.503554+00:00",
"title": "High-Privilege Remote Takeover of Oracle Applications DBA via HTTP",
"updated": "2026-09-20T10:15:05.111756+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$applications_dba"
]
},
"epss": {
"score": 0.0043
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*"
],
"created": "2026-09-15T20:03:27.577000+00:00",
"description": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/83xxx/CVE-2026-83117.json",
"references": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"title": null,
"updated": "2026-09-17T13:10:44.227000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$applications_dba"
],
"weaknesses": []
},
"nvd": {
"cpes": [],
"created": "2026-09-15T20:18:22.043000+00:00",
"description": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 7.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-83117.json",
"references": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"title": null,
"updated": "2026-09-17T14:17:33.890000+00:00",
"vendors": [],
"weaknesses": [
"CWE-269"
]
},
"opencve": {
"changes": [
{
"created": "2026-09-15T20:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$applications_dba"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$applications_dba"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 7.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "6be236c9-8775-4489-ba8b-0712cc725d9e"
},
{
"created": "2026-09-17T02:30:00+00:00",
"data": [
{
"details": {
"new": "High‑Privilege Takeover via HTTP in Oracle Applications DBA",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-264",
"CWE-284"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "49289f26-f844-4dee-9cde-0a422c254c05"
},
{
"created": "2026-09-17T14:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-269"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "1445080b-bd01-4446-b4d4-3942928011e0"
},
{
"created": "2026-09-18T21:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "High‑Privilege Takeover via HTTP in Oracle Applications DBA"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-264",
"CWE-284"
]
},
"type": "weaknesses"
}
],
"id": "b2c0d8fd-5712-4650-ac33-3494af1fceb1"
},
{
"created": "2026-09-20T10:30:00+00:00",
"data": [
{
"details": {
"new": "High-Privilege Remote Takeover of Oracle Applications DBA via HTTP",
"old": null
},
"type": "title"
}
],
"id": "ce9c10e7-3cbe-4d6a-bd98-f9cf1a3cd3ac"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:*"
],
"providers": [
"mitre"
]
},
"created": {
"data": "2026-09-15T20:03:27.577000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 7.2,
"vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.0043
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspusep2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "High-Privilege Remote Takeover of Oracle Applications DBA via HTTP",
"provider": "enrichment"
},
"updated": {
"data": "2026-09-20T10:15:05.111756+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$applications_dba"
],
"providers": [
"mitre",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-269"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2026-09-15T20:03:27.577000+00:00",
"description": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "none",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [],
"title": null,
"updated": "2026-09-17T13:02:25.487000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/83xxx/CVE-2026-83117.json",
"weaknesses": [
"CWE-269"
]
}
}