ZeroHour

CVE-2026-83115

moderate

Unauthenticated Information Disclosure in Oracle EBS Applications Manager RapidClone

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83115 is an easily exploitable information disclosure vulnerability in the RapidClone command-line component of Oracle Applications Manager, part of Oracle E-Business Suite. An unauthenticated remote attacker with network access can trigger the flaw by sending crafted HTTP requests to the vulnerable Applications Manager/RapidClone functionality, with no user interaction or privileges required. Successful attacks result in unauthorized read access to critical data or complete access to all data reachable by Oracle Applications Manager; per the CVSS vector, the impact is confidentiality only (no integrity or availability impact). Affected deployments are Oracle E-Business Suite releases 12.2.3 through 12.2.15. There is no known public proof of concept and no evidence of in-the-wild exploitation, and the CVE is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that resolves this CVE and bring affected 12.2.3-12.2.15 environments up to the latest 12.2 patch level. Do not expose Oracle Applications Manager or RapidClone functionality to the public internet; restrict access to trusted networks or behind VPN/SSO. Review HTTP access logs for unauthenticated requests to Applications Manager/RapidClone endpoints and assess what sensitive data those endpoints could have disclosed.

Affected
Oracle E-Business Suite (Oracle Applications Manager, component: Command Line - RapidClone)12.2.3-12.2.15
Estimated exposure
moderateLikely thousands of internet-exposed E-Business Suite hosts (order of magnitude ~1,000-10,000 exposed systems), plus a larger internal/on-premises install base — Oracle EBS is a self-hosted enterprise ERP; public internet scans (e.g., Shodan/Censys) historically show low-thousands of internet-facing EBS instances, and the affected 12.2.3-12.2.15 range covers the most commonly deployed release…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.