ZeroHour

CVE-2026-83162

moderate

Unauthenticated Data Access and Tampering Flaw in Oracle E-Business Suite Core

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

A difficult-to-exploit, unauthenticated vulnerability exists in the Core component of the Oracle Application Object Library, part of Oracle E-Business Suite, reachable over HTTPS by a remote attacker with network access. Successful exploitation lets the attacker create, delete, or modify critical data — up to all data accessible through the Application Object Library — as well as read that data without authorization. Organizations running Oracle E-Business Suite 12.2 versions 12.2.3 through 12.2.15 are affected. The high attack-complexity rating (AC:H) means exploitation requires favorable conditions, which limits reliable real-world attacks, but the impact on confidentiality and integrity of business data is high (CVSS 7.4). There is no known public proof-of-concept, the flaw is not on CISA's KEV list, and no exploitation in the wild has been reported.

What to do: Apply Oracle's latest Critical Patch Update for E-Business Suite 12.2 and confirm the Application Object Library is patched beyond the affected 12.2.3–12.2.15 range. Because the flaw is exploitable over HTTPS without authentication, restrict internet-facing exposure of EBS web entry points (self-service, supplier, and recruitment portals) to VPN or IP allowlists. Review Application Object Library data and audit logs for any unexplained creation, deletion, or modification of records.

Affected
Oracle Application Object Library (Oracle E-Business Suite), Core component12.2.3-12.2.15
Estimated exposure
moderatelikely thousands (order 1,000–10,000) of internet-reachable EBS web endpoints, out of an estimated tens of thousands of on-premises installations — Based on public internet scan data that has historically shown a few thousand Oracle E-Business Suite web entry points exposed over HTTPS, set against an enterprise customer base estimated in the tens of thousands of installations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.