Description
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Immediately
AI Analysis

Impact

A vulnerability in Oracle Marketing’s Audience component allows an attacker with low privileges and network access via HTTP to read and modify marketing data. The weakness stems from missing or incorrect application‑level authorization controls (CWE‑284). Successful exploitation can lead to confidential data exposure (high confidentiality impact) as well as unauthorized insert, update or delete operations, affecting data integrity.

Affected Systems

Oracle Corporation’s Oracle Marketing product, part of Oracle E‑Business Suite, is affected. Supported releases from version 12.2.3 through 12.2.15 are susceptible to this flaw. The vulnerability resides in the Audience component, and because the scope change may be broadened, other Oracle Marketing services on the same installation may also be impacted.

Risk and Exploitability

The CVSS 3.1 base score of 8.5 signifies a high severity assessment, while an EPSS score of less than 1% indicates a low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers need only low privileges over an HTTP connection, and a successful attack grants extensive read and write capabilities across all Oracle Marketing data. Despite the low exploitation likelihood, the potential for widespread data compromise warrants immediate remediation.

Generated by OpenCVE AI on September 20, 2026 at 10:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check Oracle’s security advisory for available patches and apply the latest update to Oracle Marketing.
  • Restrict HTTP access to the Oracle Marketing application to trusted networks or enforce firewall rules to block untrusted traffic.
  • Enforce application‑level authorization checks to ensure only authenticated users can perform insert, update or delete operations on marketing data.

Generated by OpenCVE AI on September 20, 2026 at 10:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Exploit Enabling Unauthorized Data Access in Oracle Marketing

Thu, 17 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low Privileged HTTP Exploit Enabling Unauthorized Data Access in Oracle Marketing

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle marketing
CPEs cpe:2.3:a:oracle:marketing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle marketing
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Marketing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:58:44.033Z

Reserved: 2026-08-31T15:40:57.338Z

Link: CVE-2026-83083

cve-icon Vulnrichment

Updated: 2026-09-16T17:55:52.231Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:18.067

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:15:05Z

Weaknesses