CVE-2026-62534: High severity Oracle Oracle Applications Framework vulnerability
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite (Oracle Applications Framework) - Web Utilitiesto a version that resolves this vulnerability.Fixed in 12.2.11-12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62534?
CVE-2026-62534 has a high severity score of 8.8.
Which versions are affected by CVE-2026-62534?
CVE-2026-62534 affects Oracle E-Business Suite versions 12.2.11 through 12.2.15.
How do I fix CVE-2026-62534?
To fix CVE-2026-62534, update the affected Oracle Applications Framework to a patched version provided by Oracle.
What type of attack can exploit CVE-2026-62534?
CVE-2026-62534 can be exploited by low privileged attackers with network access via HTTP.
What components are involved in CVE-2026-62534?
CVE-2026-62534 involves a vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite.