CVE-2026-83341
moderateUnauthenticated Info Leak in Oracle E-Business Suite Applications Manager RapidClone
CVE-2026-83341 is a vulnerability in the Command Line - RapidClone component of Oracle Applications Manager, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by an unauthenticated attacker with network access via HTTP, who can compromise Oracle Applications Manager without any credentials or user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data; per the CVSS 3.1 vector (7.5, AV:N/AC:L/PR:N/UI:N), the impact is limited to high confidentiality loss with no integrity or availability impact. Organizations running affected E-Business Suite 12.2 versions with the Applications Manager interface reachable over the network are exposed. The flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof of concept is known, suggesting exploitation has not been observed in the wild.
What to do: Apply the Oracle Critical Patch Update that remediated this CVE to all E-Business Suite 12.2.3-12.2.15 environments, prioritizing instances where Applications Manager is reachable over HTTP. Until patched, remove the Applications Manager and RapidClone endpoints from internet exposure and restrict access to trusted admin networks via firewall or VPN. Review HTTP access logs for unauthenticated requests to Applications Manager URIs and verify no unexpected data access has occurred.
| Oracle E-Business Suite (Oracle Applications Manager, component: Command Line - RapidClone) | 12.2.3 - 12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.