ZeroHour

CVE-2026-83457

niche

Low-Privilege Data Tampering and DoS Flaw in Oracle Demand Signal Repository

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83457 is an easily exploitable vulnerability in the Internal Operations component of Oracle Demand Signal Repository (DSR), a product within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. A remote attacker who already holds a low-privileged account and has HTTP network access to the application can trigger the flaw without user interaction. Successful exploitation lets the attacker create, delete, or modify critical DSR data and cause a hang or repeatable crash resulting in complete denial of service of the repository, though no confidentiality impact is expected. Organizations running affected EBS 12.2 deployments with the DSR product exposed to users over the network are at risk. The issue is not on the CISA KEV list and no public proof-of-concept or observed in-the-wild exploitation is known.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83457 to all DSR installations on EBS 12.2.3-12.2.15. Restrict HTTP access to the EBS/DSR application tier to trusted networks and VPNs rather than broad internet exposure, and review low-privileged DSR accounts for necessity. Monitor DSR data for unauthorized changes and watch for repeated crashes or hangs that could indicate exploitation attempts.

Affected
Oracle Demand Signal Repository (Oracle E-Business Suite)12.2.3-12.2.15
Estimated exposure
nichelikely hundreds to low thousands of installations globally — Demand Signal Repository is an optional, specialized E-Business Suite module used mainly by consumer-goods and manufacturing enterprises, so it represents only a small fraction of the tens of thousands of organizations running EBS overall.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.