CVE-2026-83455
nicheAuthenticated Data Manipulation Flaw in Oracle Demand Signal Repository 12.2
Oracle Demand Signal Repository (DSR), a product within Oracle E-Business Suite, contains a vulnerability in its Internal Operations component affecting supported versions 12.2.3 through 12.2.15. A remote attacker who already holds a low-privileged account can exploit it easily over HTTP without any user interaction, requiring no special conditions. Successful exploitation lets the attacker create, delete, or modify critical DSR data (or all DSR-accessible data) and also read critical data or gain complete read access to DSR data. Any organization running an affected EBS DSR deployment exposed to users on the network is at risk, though the attack requires valid low-level credentials. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses this CVE to all Oracle Demand Signal Repository installations on EBS 12.2.3-12.2.15 (or upgrade beyond the affected 12.2.x range). Restrict HTTP access to EBS/DSR endpoints to trusted networks and VPNs, audit low-privileged account activity in DSR for unexpected data creation, modification, or deletion, and enforce least-privilege role assignments in EBS responsibilities. Review Oracle's advisory for patch availability and interim mitigation guidance.
| Oracle Demand Signal Repository (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.