ZeroHour

CVE-2026-83341

moderate

Unauthenticated Info Leak in Oracle E-Business Suite Applications Manager RapidClone

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83341 is a vulnerability in the Command Line - RapidClone component of Oracle Applications Manager, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker with network access via HTTP, who can compromise Oracle Applications Manager without any credentials or user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data; per the CVSS 3.1 vector (7.5, AV:N/AC:L/PR:N/UI:N), the impact is limited to high confidentiality loss with no integrity or availability impact. Organizations running affected E-Business Suite 12.2 versions with the Applications Manager interface reachable over the network are exposed. The flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof of concept is known, suggesting exploitation has not been observed in the wild.

What to do: Apply the Oracle Critical Patch Update that remediated this CVE to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances where Applications Manager is reachable over HTTP. Until patched, remove the Applications Manager and RapidClone endpoints from internet exposure and restrict access to trusted admin networks via firewall or VPN. Review HTTP access logs for unauthenticated requests to Applications Manager URIs and verify no unexpected data access has occurred.

Affected
Oracle E-Business Suite (Oracle Applications Manager, component: Command Line - RapidClone)12.2.3 - 12.2.15
Estimated exposure
moderate≈ low thousands of internet-exposed E-Business Suite instances; plausibly tens of thousands of installations globally — Oracle EBS is on-premises enterprise software deployed at tens of thousands of organizations, while public internet scans (Shodan/Censys) have historically shown only a few thousand internet-facing EBS endpoints, and Applications Manager…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.