Description
Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Partner Management. While the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Partner Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Apply Patch
AI Analysis

Impact

A flaw in the Oracle Partner Management component of Oracle E‑Business Suite allows a low‑privileged attacker with network access over HTTP to bypass authentication controls and gain unauthorized read or write access to data that the application exposes. The weakness is an improper allocation of permissions, identified as CWE‑284, and results in confidentiality compromise and the possibility of altering or deleting critical records. The vulnerability does not directly affect application availability but enables an attacker to view or modify data that should be tightly controlled.

Affected Systems

Oracle Partner Management, a component of Oracle E‑Business Suite, is affected. Supported versions from 12.2.3 through 12.2.15 are potentially vulnerable.

Risk and Exploitability

The CVSS base score of 7.1 places the issue in the high‑severity range, while the EPSS score of < 1% indicates that exploitation attempts are currently expected to be rare. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely exploit this via unauthenticated HTTP traffic, and the scope of the weakness may extend to other products within the Oracle suite if access controls are similarly weak.

Generated by OpenCVE AI on September 18, 2026 at 21:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the patch or upgrade Oracle Partner Management to a fixed version as detailed in the Oracle security advisory (https://www.oracle.com/security-alerts/cspusep2026.html).
  • Reconfigure Oracle Partner Management HTTP endpoints to require authentication and enforce least‑privilege access, which directly addresses the improper access control weakness.
  • Restrict inbound HTTP traffic to Oracle Partner Management by applying network segmentation and firewall rules that allow only trusted IP ranges to reach the affected services.

Generated by OpenCVE AI on September 18, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Network Client Compromise of Oracle Partner Management via Unauthenticated HTTP Exploit

Thu, 17 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Network Client Compromise of Oracle Partner Management via Unauthenticated HTTP Exploit

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Partner Management. While the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Partner Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle partner Management
CPEs cpe:2.3:a:oracle:partner_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle partner Management
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Partner Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:57:49.656Z

Reserved: 2026-08-31T15:40:57.340Z

Link: CVE-2026-83111

cve-icon Vulnrichment

Updated: 2026-09-16T17:56:08.767Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:21.330

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:30:14Z

Weaknesses