Description
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Oracle Spares Management allows an attacker with compromise of the application. The impact includes a loss of confidentiality, integrity, and availability, as the attacker can access, modify, or delete critical data. This is a high‑severity flaw, scored at 8.8 on CVSS 3.1, indicating a severe threat if exploited. Key weakness type is improper access control, allowing privileged escalation from a low‑privileged state.

Affected Systems

Oracle Corporation’s Oracle Spares Management product for Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, is affected. The security alert specifies that only these supported versions are vulnerable and that exploitation is possible via the internal operations component exposed to the network.

Risk and Exploitability

This flaw poses a serious risk to organizations that use the affected Oracle E‑Business Suite instances. The EPSS score of <1% indicates a very low current exploitation probability, but the high CVSS score of 8.8 shows significant potential impact if exploited. The vulnerability is not listed in CISA KEV catalog. It should be fully remediated as quickly as possible.

Generated by OpenCVE AI on September 18, 2026 at 20:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Spares Management patch released for versions 12.2.3 to 12.2.15 immediately.
  • Restrict network access to the Oracle Spares Management HTTP endpoint by limiting inbound traffic to trusted hosts and network segments.
  • If immediate patching is not possible, enforce strict role‑based access controls and disable unnecessary HTTP services on the instance to reduce exposure.

Generated by OpenCVE AI on September 18, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Spares Management low‑privilege HTTP takeover

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Oracle Spares Management low‑privilege HTTP takeover
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle spares Management
CPEs cpe:2.3:a:oracle:spares_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle spares Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Spares Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:20:18.692Z

Reserved: 2026-08-31T15:40:57.339Z

Link: CVE-2026-83090

cve-icon Vulnrichment

Updated: 2026-09-17T14:59:00.498Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:18.840

Modified: 2026-09-17T16:18:00.370

Link: CVE-2026-83090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:00:15Z

Weaknesses