ZeroHour

CVE-2026-83072

moderate

Authenticated Data Manipulation Flaw in Oracle E-Business Suite Applications Framework

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

The Oracle Applications Framework component of Oracle E-Business Suite contains an easily exploitable flaw in the Search Bean (including Advanced) component. A low-privileged attacker with network access via HTTP who triggers the flaw can compromise the Applications Framework, gaining unauthorized ability to create, delete, or modify critical data as well as read access to critical data or all framework-accessible data. Deployments running E-Business Suite releases 12.2.3 through 12.2.15 are affected. The issue carries a CVSS 3.1 base score of 8.1 (high), is not on CISA's Known Exploited Vulnerabilities list, and no public proof of concept is known, so exploitation in the wild is not currently observed.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw — every listed release (12.2.3–12.2.15) is affected, so patching is required rather than a version upgrade within that range. Restrict HTTP access to EBS/OAF pages, especially self-service and search endpoints, to trusted networks or VPN, and minimize low-privilege account sprawl since exploitation requires only an authenticated session. Review audit logs for anomalous Search Bean / Advanced Search activity and unexpected data changes made by low-privilege users.

Affected
Oracle Applications Framework (Oracle E-Business Suite), component: Search Bean [Incl. Advanced]12.2.3-12.2.15
Estimated exposure
moderate≈ low thousands of internet-exposed EBS instances, with a larger internal-only installed base — Oracle E-Business Suite is on-premises enterprise software whose HTTP/OAF endpoints are typically internal-facing, and public internet scan datasets have historically shown only a few thousand EBS web endpoints exposed, so the directly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.