ZeroHour

CVE-2026-83172

niche

Authenticated data exposure flaw in Oracle Sales Online 12.2.3-12.2.15 (EBS)

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83172 is a high-severity (CVSS 3.1: 8.5) vulnerability in the OSO Other component of Oracle Sales Online, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. A remote attacker holding only low-privileged (valid, unprivileged) credentials can trigger the flaw over HTTP, and because the vulnerability changes scope, the impact can extend beyond Oracle Sales Online into additional products on the EBS stack. Successful attacks can yield unauthorized read access to critical data or complete access to all Oracle Sales Online-accessible data, as well as unauthorized insert, update, or delete access to some of that data; availability is not impacted. Organizations running affected EBS 12.2 releases with Oracle Sales Online enabled are at risk, particularly where the EBS web tier is reachable from untrusted networks. No public proof of concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update remediation for CVE-2026-83172 to all EBS environments on 12.2.3-12.2.15 that have Oracle Sales Online installed. Until patched, restrict HTTP access to the EBS web tier to trusted networks or VPN, review and minimize low-privileged OSO responsibilities, and audit application logs for anomalous cross-module data reads or unexpected inserts/updates/deletes by low-privilege accounts.

Affected
Oracle Sales Online (Oracle E-Business Suite, component: OSO Other)12.2.3-12.2.15
Estimated exposure
nichelikely hundreds to a few thousand environments worldwide (subset of EBS installs running Sales Online) — Oracle E-Business Suite is enterprise data-center software with a deployment base in the tens of thousands of organizations, public internet scans typically show only low thousands of EBS web tiers exposed, and Sales Online is an optional…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: OSO Other). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online. While the vulnerability is in Oracle Sales Online, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Sales Online accessible data as well as unauthorized update, insert or delete access to some of Oracle Sales Online accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.