ZeroHour

CVE-2026-83487

moderate

Authenticated Data Exposure in Oracle Product Hub 12.2.3-12.2.15 (E-Business Suite)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83487 is an information disclosure vulnerability in the Item Catalog component of Oracle Product Hub, part of Oracle E-Business Suite, affecting releases 12.2.3 through 12.2.15. It is rated easily exploitable: a low-privileged (authenticated) attacker with HTTP network access to the E-Business Suite environment can trigger the flaw without user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data, and because the issue has a scope change, the confidentiality impact can extend beyond Product Hub to additional products. The vulnerability is confidentiality-only (CVSS 3.1 score 7.7; no integrity or availability impact), so attackers read sensitive data but do not modify or disrupt it. No public proof of concept is known, the CVE is not on CISA's KEV list, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE to all Oracle E-Business Suite 12.2.3-12.2.15 environments running Product Hub. Restrict HTTP/HTTPS access to EBS to trusted networks or VPN, enforce least-privilege roles for accounts that can reach the Item Catalog, and review audit logs for anomalous data-access patterns by low-privilege accounts. Verify the patch level of every EBS instance, including test and development environments that may also expose Product Hub.

Affected
Oracle Product Hub (Oracle E-Business Suite), Item Catalog component12.2.3-12.2.15
Estimated exposure
moderate≈ tens of thousands of organizations running E-Business Suite on-premises, with likely only low thousands of Product Hub/EBS web endpoints internet-exposed — Oracle E-Business Suite is on-premises enterprise ERP software deployed at an estimated tens of thousands of organizations worldwide, while public internet scan data typically shows only a few thousand internet-reachable EBS instances; the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.