ZeroHour

CVE-2026-83352

moderate

Authenticated Data Exposure and Partial DoS in Oracle E-Business Suite XML Gateway

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83352 is a high-severity (CVSS 7.1) flaw in the Install component of Oracle XML Gateway, part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. It is easily exploitable by a low-privileged (authenticated) attacker who has network access to the EBS instance over HTTP. A successful attack lets the attacker read critical data or all data accessible through Oracle XML Gateway, and to cause a partial denial of service of the XML Gateway component; integrity is not impacted per the CVSS vector. Organizations running affected 12.2.x releases with the XML Gateway component installed and reachable over the network are at risk. The vulnerability is not on the CISA KEV list, no public proof-of-concept is known, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update (CPU) that addresses CVE-2026-83352 to all E-Business Suite 12.2.3-12.2.15 environments running Oracle XML Gateway. Restrict HTTP access to EBS/XML Gateway endpoints to trusted networks or VPN, and review EBS audit and access logs for anomalous activity by low-privilege accounts against XML Gateway. Verify the XML Gateway component is actually installed and patched on each instance, as it may be optional in some deployments.

Affected
Oracle E-Business Suite XML Gateway (component: Install)12.2.3 - 12.2.15
Estimated exposure
moderateThousands of organizations (order of 1k-10k internet-reachable EBS instances, plus many more internal deployments) — Oracle E-Business Suite is deployed at roughly tens of thousands of enterprises worldwide, and public internet scans typically show a few thousand EBS instances (login pages/XML Gateway endpoints) exposed over HTTP, though most run behind…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.