CVE-2026-83332
moderateAuthenticated Data Access Flaw in Oracle E-Business Suite Applications Framework
Oracle E-Business Suite's Oracle Applications Framework (OAF), specifically the Personalization component, contains an easily exploitable vulnerability in versions 12.2.9 through 12.2.15. A low-privileged, authenticated attacker with network access via HTTP can trigger the flaw to compromise the Applications Framework. A successful attack yields unauthorized read access to critical data — or complete access to all OAF-accessible data — as well as unauthorized update, insert, and delete access to some OAF-accessible data. Organizations running affected E-Business Suite 12.2 releases with the framework reachable over HTTP/HTTPS are exposed, particularly if self-service or partner accounts exist. No public proof-of-concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply the Oracle Critical Patch Update that addresses this vulnerability to all Oracle E-Business Suite 12.2.9-12.2.15 environments, as Oracle patches OAF via its CPU cycle rather than standalone version bumps. Restrict HTTP/HTTPS access to OAF pages at the perimeter (VPN/IP allow-listing) and audit low-privilege account permissions to reduce the pool of usable credentials. Review Personalization and application audit logs for anomalous bulk reads or unauthorized data modification by low-privileged accounts.
| Oracle Applications Framework (Oracle E-Business Suite, component: Personalization) | 12.2.9-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.