CVE-2026-83457
nicheLow-Privilege Data Tampering and DoS Flaw in Oracle Demand Signal Repository
CVE-2026-83457 is an easily exploitable vulnerability in the Internal Operations component of Oracle Demand Signal Repository (DSR), a product within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A remote attacker who already holds a low-privileged account and has HTTP network access to the application can trigger the flaw without user interaction. Successful exploitation lets the attacker create, delete, or modify critical DSR data and cause a hang or repeatable crash resulting in complete denial of service of the repository, though no confidentiality impact is expected. Organizations running affected EBS 12.2 deployments with the DSR product exposed to users over the network are at risk. The issue is not on the CISA KEV list and no public proof-of-concept or observed in-the-wild exploitation is known.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83457 to all DSR installations on EBS 12.2.3-12.2.15. Restrict HTTP access to the EBS/DSR application tier to trusted networks and VPNs rather than broad internet exposure, and review low-privileged DSR accounts for necessity. Monitor DSR data for unauthorized changes and watch for repeated crashes or hangs that could indicate exploitation attempts.
| Oracle Demand Signal Repository (Oracle E-Business Suite) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.