Executive brief
A vulnerability exists in the Oracle Mobile Application Server, a component of Oracle E-Business Suite used to manage mobile device connections to enterprise applications. A high-privileged attacker could exploit this flaw to gain unauthorized access to sensitive business data or cause a complete service outage. This could disrupt warehouse or logistics operations that rely on mobile terminals for real-time data entry and processing.
Technical details
This vulnerability affects the MWA Terminal Server component of the Oracle Mobile Application Server within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires high-privileged administrative credentials and network access via HTTP. An attacker successfully exploiting this issue can achieve full read access to all data accessible by the server, partial unauthorized modification or deletion of data, and the ability to trigger a persistent denial-of-service (DoS) condition by crashing or hanging the server. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Mobile Application Server (MWA Terminal Server) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60846 was published to the NVD.