ZeroHour

CVE-2026-83142

moderate

Authenticated Information Disclosure in Oracle E-Business Suite Proposals

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83142 is a high-severity (CVSS 3.1: 7.7) information disclosure flaw in the Internal Operations component of Oracle Proposals, which is part of Oracle E-Business Suite. It is triggered by a low-privileged, authenticated attacker interacting with the vulnerable component over the network via HTTP, with no user interaction required. A successful attack results in unauthorized access to critical data or complete access to all Oracle Proposals accessible data, and because the vulnerability carries a scope change (S:C), successful attacks may also significantly impact additional Oracle E-Business Suite products beyond Oracle Proposals. The impact is purely on confidentiality — there is no integrity or availability effect. There is no known public proof-of-concept, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.

What to do: Apply the latest Oracle Critical Patch Update that remediates this issue for Oracle E-Business Suite 12.2 and confirm the patch level covers Oracle Proposals versions 12.2.3-12.2.15. Restrict HTTP/HTTPS access to EBS environments (VPN or IP allowlisting) and enforce least-privilege role assignments so ordinary accounts cannot reach sensitive Proposals data. Review EBS audit and access logs for anomalous data reads by low-privileged users of the Proposals/Internal Operations component.

Affected
Oracle E-Business Suite (Oracle Proposals, Internal Operations component)12.2.3 - 12.2.15
Estimated exposure
moderateLow thousands of internet-exposed E-Business Suite instances out of an estimated tens of thousands of on-premises deployments; the subset running the Proposals… — Oracle E-Business Suite is an on-premises enterprise ERP deployed by an estimated tens of thousands of organizations worldwide, public internet scans typically show only a few thousand exposed EBS web endpoints, and exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Proposals. While the vulnerability is in Oracle Proposals, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Proposals accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.