ZeroHour

CVE-2026-83136

moderate

Authenticated Takeover Flaw in Oracle E-Business Suite Spares Management 12.2

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

A high-severity (CVSS 8.8) vulnerability in the Internal Operations component of Oracle Spares Management, part of Oracle E-Business Suite, allows a low-privileged authenticated attacker with HTTP network access to fully compromise the Spares Management product. Exploitation is rated as easy (low attack complexity, no user interaction), meaning any valid account with minimal privileges on an affected instance is sufficient. A successful attack results in complete takeover, with high impact on confidentiality, integrity, and availability of the affected module. All E-Business Suite 12.2.3 through 12.2.15 installations running Spares Management are affected. No public proof-of-concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no known in-the-wild exploitation to date.

What to do: Apply the Oracle Critical Patch Update that addresses this flaw to all E-Business Suite 12.2.3-12.2.15 environments running Spares Management, and verify the Internal Operations component is included in the patch coverage. Restrict HTTP access to EBS via network segmentation or a reverse proxy so the module is not reachable by untrusted networks, and review low-privileged account activity in Spares Management for signs of abuse. Oracle's standard guidance is to apply the latest cumulative CPU rather than individual patches.

Affected
Oracle Spares Management (Oracle E-Business Suite), component: Internal Operations12.2.3 - 12.2.15
Estimated exposure
moderatethousands of EBS 12.2.x deployments; an unknown subset running Spares Management (likely hundreds to low thousands) — Oracle E-Business Suite 12.2 is widely deployed in large enterprises but public internet scans typically show only a few thousand internet-facing EBS instances, and Spares Management is a niche field-service/depot-repair module, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.