ZeroHour

CVE-2026-87125

moderate

Authenticated Data Tampering Flaw in Oracle EBS Financials for Asia/Pacific

CVSS 3.1
8.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87125 is a high-severity (CVSS 8.3) vulnerability in the Internal Operations component of Oracle Financials for Asia/Pacific, part of Oracle E-Business Suite releases 12.2.8 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. A successful attack allows the attacker to create, delete, or modify critical data within the product, gain unauthorized read access to all data accessible to it, and cause a partial denial of service. Organizations running affected 12.2.x releases with this APAC-localized financials module are at risk, particularly if EBS web tiers are reachable from broader networks. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so no exploitation is currently known.

What to do: Apply the Oracle Critical Patch Update that remedies this flaw to all E-Business Suite 12.2.8-12.2.15 environments running Financials for Asia/Pacific. Restrict HTTP access to EBS web tiers (VPN/IP allowlisting) and enforce least-privilege on application accounts, since exploitation requires only a low-privileged login. Review audit and data-change logs in the module for unauthorized modifications or access preceding the patch.

Affected
Oracle Financials for Asia/Pacific (Oracle E-Business Suite, component: Internal Operations)12.2.8-12.2.15
Estimated exposure
moderatelikely low thousands of deployments (subset of E-Business Suite installs running the Asia/Pacific localized financials module) — Oracle E-Business Suite is deployed at tens of thousands of enterprises but this is a regional APAC-localized financials module, and public internet scans typically show only a few thousand internet-exposed EBS web endpoints, so the truly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for Asia/Pacific. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials for Asia/Pacific accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials for Asia/Pacific accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financials for Asia/Pacific. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.