CVE-2026-83162
moderateUnauthenticated Data Access and Tampering Flaw in Oracle E-Business Suite Core
A difficult-to-exploit, unauthenticated vulnerability exists in the Core component of the Oracle Application Object Library, part of Oracle E-Business Suite, reachable over HTTPS by a remote attacker with network access. Successful exploitation lets the attacker create, delete, or modify critical data — up to all data accessible through the Application Object Library — as well as read that data without authorization. Organizations running Oracle E-Business Suite 12.2 versions 12.2.3 through 12.2.15 are affected. The high attack-complexity rating (AC:H) means exploitation requires favorable conditions, which limits reliable real-world attacks, but the impact on confidentiality and integrity of business data is high (CVSS 7.4). There is no known public proof-of-concept, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported.
What to do: Apply Oracle's latest Critical Patch Update for E-Business Suite 12.2 and confirm the Application Object Library is patched beyond the affected 12.2.3–12.2.15 range. Because the flaw is exploitable over HTTPS without authentication, restrict internet-facing exposure of EBS web entry points (self-service, supplier, and recruitment portals) to VPN or IP allowlists. Review Application Object Library data and audit logs for any unexplained creation, deletion, or modification of records.
| Oracle Application Object Library (Oracle E-Business Suite), Core component | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.