Unauthorized Data Access Vulnerability in Oracle E-Business Suite
CVE-2026-21960
6.5MEDIUM
What is CVE-2026-21960?
A vulnerability in the Java utils component of the Oracle Applications DBA product within the Oracle E-Business Suite allows an attacker with elevated privileges and network access via HTTP to exploit the system. Successful exploitation can lead to unauthorized data manipulation, including the creation, deletion, or modification of sensitive data. This vulnerability poses serious risks to the integrity and confidentiality of data managed by the Oracle Applications DBA.
Affected Version(s)
Oracle Applications DBA 12.2.3 <= 12.2.15