CVE-2026-87125
moderateAuthenticated Data Tampering Flaw in Oracle EBS Financials for Asia/Pacific
CVE-2026-87125 is a high-severity (CVSS 8.3) vulnerability in the Internal Operations component of Oracle Financials for Asia/Pacific, part of Oracle E-Business Suite releases 12.2.8 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, requiring no user interaction. A successful attack allows the attacker to create, delete, or modify critical data within the product, gain unauthorized read access to all data accessible to it, and cause a partial denial of service. Organizations running affected 12.2.x releases with this APAC-localized financials module are at risk, particularly if EBS web tiers are reachable from broader networks. No public proof-of-concept exists and the flaw is not on the CISA KEV list, so no exploitation is currently known.
What to do: Apply the Oracle Critical Patch Update that remedies this flaw to all E-Business Suite 12.2.8-12.2.15 environments running Financials for Asia/Pacific. Restrict HTTP access to EBS web tiers (VPN/IP allowlisting) and enforce least-privilege on application accounts, since exploitation requires only a low-privileged login. Review audit and data-change logs in the module for unauthorized modifications or access preceding the patch.
| Oracle Financials for Asia/Pacific (Oracle E-Business Suite, component: Internal Operations) | 12.2.8-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for Asia/Pacific. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials for Asia/Pacific accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials for Asia/Pacific accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financials for Asia/Pacific. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.