Executive brief
Oracle Mobile Application Server (MWA Terminal Server), a component of Oracle E-Business Suite used to manage mobile access to enterprise applications, contains an easily exploitable vulnerability accessible over the network without authentication. Attackers can exploit this flaw to access sensitive business data or temporarily disrupt service availability, compromising the confidentiality and availability of critical enterprise information.
Technical details
The vulnerability in Oracle Mobile Application Server (versions 12.2.3–12.2.15) permits unauthenticated network attackers with TCP access to compromise the application and access protected data. The flaw requires no authentication, no complex configuration, and can be exploited via network-accessible TCP endpoints in the MWA Terminal Server component. Successful exploitation results in unauthorized access to confidential data and partial denial of service. The CVSS 3.1 score of 8.2 reflects high confidentiality and availability impacts. Patches are expected from Oracle; consult official Oracle security advisories for remediation timelines and availability.
Affected products
- Oracle E-Business Suite Mobile Application Server 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed