Description
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Manipulation and Access
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Search Bean component of Oracle Applications Framework allows a low‑privileged attacker with network access via HTTP to gain unauthorized ability to create, delete, or modify critical data and to access all data exposed by the framework. The weakness, identified as CWE-284, stems from insecure permission handling that does not restrict these actions to privileged users. Successful exploitation can lead to significant confidentiality and integrity violations, potentially affecting all data accessible through the framework.

Affected Systems

Oracle Applications Framework version 12.2.3 through 12.2.15 are affected. These releases are part of Oracle E‑Business Suite and are supported for use by enterprise applications.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 indicates a high severity vulnerability. The EPSS score is reported as < 1 %, implying a low probability of exploitation at present, and it is not listed in the CISA KEV catalog. Nonetheless, the attack vector is network‑based via HTTP, and the low privileged attacker requirement means that anyone with network reach to the application, even with minimal credentials, can potentially exploit the flaw. An attacker who succeeds could alter or delete critical business data or gain full access to the framework’s data store.

Generated by OpenCVE AI on September 17, 2026 at 20:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Applications Framework patch that fixes the Search Bean vulnerability.
  • Limit or secure HTTP access to the Search Bean component, ensuring that only authenticated users with appropriate roles can invoke it.
  • Enforce strict role‑based access control on all critical data and regularly audit permissions for the framework components.
  • Monitor application logs for anomalous data manipulation activities and investigate any suspicious events promptly.

Generated by OpenCVE AI on September 17, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Search Bean Vulnerability in Oracle Applications Framework

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Advanced]). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Applications Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle applications Framework
CPEs cpe:2.3:a:oracle:applications_framework:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Framework
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Applications Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:21:19.970Z

Reserved: 2026-08-31T15:40:57.338Z

Link: CVE-2026-83072

cve-icon Vulnrichment

Updated: 2026-09-17T14:59:13.656Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:16.113

Modified: 2026-09-17T16:17:55.240

Link: CVE-2026-83072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses