ZeroHour

CVE-2026-83345

moderate

Low-Privilege Data Access and Partial DoS in Oracle E-Business Suite XML Gateway 12.2

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

Oracle E-Business Suite's XML Gateway product (Install component) contains an easily exploitable flaw affecting releases 12.2.3 through 12.2.15. A low-privileged attacker — i.e., one holding a valid, low-level account — with network access via HTTP can trigger the flaw to compromise Oracle XML Gateway, resulting in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data, plus the ability to cause a partial denial of service. The issue carries a CVSS 3.1 base score of 7.1 (high), with high confidentiality and low availability impact and no integrity impact. Organizations running affected E-Business Suite 12.2 releases with XML Gateway exposed over the network are at risk, particularly if the HTTP endpoints are reachable by broad user populations. There is no known public proof-of-concept, the flaw is not on the CISA Known Exploited Vulnerabilities list, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83345 to all Oracle E-Business Suite 12.2.3–12.2.15 environments running XML Gateway. Restrict HTTP access to XML Gateway endpoints (e.g., via network segmentation, allow-listing, or Web Entry Point/WAF rules) so only trusted internal users and integration partners can reach them. Review XML Gateway logs for anomalous data access or unexpected traffic patterns from low-privilege accounts, and verify that EBS Self Service / gateway URLs are not unnecessarily internet-exposed.

Affected
Oracle E-Business Suite XML Gateway (component: Install)12.2.3-12.2.15
Estimated exposure
moderate≈ thousands of internet-facing Oracle EBS installations (order of 1,000–10,000 systems) — Oracle E-Business Suite is enterprise software with a large but finite install base; public internet scans (e.g., Shodan/Censys) have historically shown only a few thousand EBS login endpoints exposed, of which the subset running XML…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.