CVE-2026-83123
moderateLow-Privilege Data Exposure and Partial DoS in Oracle Report Manager (EBS 12.2)
CVE-2026-83123 is a vulnerability in the Internal Operations component of Oracle Report Manager, part of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker with network access via HTTPS, requiring no user interaction. A successful attack allows the attacker to read critical data — potentially all data accessible through Oracle Report Manager — and to cause a partial denial of service of the product (CVSS 3.1 base score 7.1; confidentiality high, availability low, no integrity impact). Organizations running affected E-Business Suite 12.2 releases with Oracle Report Manager licensed and reachable over HTTPS are at risk. There is no known public proof of concept and no indication of in-the-wild exploitation; the flaw is not on the CISA Known Exploited Vulnerabilities list.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83123 to all E-Business Suite 12.2.3-12.2.15 environments running Report Manager. Until patched, restrict HTTPS access to the EBS application tier via VPN or IP allowlisting so the component is not reachable by low-privilege or external accounts. Review user responsibilities for least privilege and check audit and access logs for anomalous Report Manager data reads or partial denial-of-service symptoms.
| Oracle Report Manager (Oracle E-Business Suite), component: Internal Operations | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Report Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Report Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.