Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications DBA, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpuapr2026.html |
|
History
Wed, 22 Apr 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High‑Privilege Remote Takeover via HTTP in Oracle Applications DBA |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications DBA, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications DBA. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle applications Dba |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:oracle:applications_dba:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle applications Dba |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-04-22T03:56:20.912Z
Reserved: 2026-01-05T18:07:34.727Z
Link: CVE-2026-22011
Updated: 2026-04-21T22:46:15.856Z
Status : Received
Published: 2026-04-21T21:16:27.740
Modified: 2026-04-21T23:16:19.620
Link: CVE-2026-22011
No data.
OpenCVE Enrichment
Updated: 2026-04-22T05:30:09Z