ZeroHour

CVE-2026-83164

moderate

Authenticated Takeover Flaw in Oracle E-Business Suite Customer Interaction History

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle Customer Interaction History, a module of Oracle E-Business Suite (Outcome-Result component), contains an easily exploitable vulnerability in supported versions 12.2.3 through 12.2.15. A remote attacker who already holds a low-privileged account and can reach the EBS web tier over HTTP can trigger the flaw, and successful attacks result in a complete takeover of Oracle Customer Interaction History. The issue carries a CVSS 3.1 base score of 8.8 with high confidentiality, integrity, and availability impacts, meaning an attacker could read, alter, or destroy data handled by the module. Organizations running the affected EBS 12.2 releases with this module in use are at risk, particularly where EBS web endpoints are reachable by broad user populations. No public proof-of-concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83164 if you run E-Business Suite 12.2.3-12.2.15 with Customer Interaction History, and confirm your bundle patch level afterwards. Restrict HTTP access to the EBS application tier to trusted networks or VPN rather than exposing it to the open internet. Review audit logs for unusual activity by low-privileged accounts interacting with Customer Interaction History / Outcome-Result pages.

Affected
Oracle Customer Interaction History (Oracle E-Business Suite, component: Outcome-Result)12.2.3-12.2.15
Estimated exposure
moderatelow-thousands of internet-facing Oracle EBS instances; vulnerable subset (CIH module on 12.2.3-12.2.15) is smaller — Internet-wide scan services typically surface several thousand internet-exposed Oracle E-Business Suite deployments, and only those running the Customer Interaction History module on affected 12.2 bundle levels are vulnerable — clearly an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks of this vulnerability can result in takeover of Oracle Customer Interaction History. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.