Description
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Report Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Takeover
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Oracle Report Manager allows a low‑privileged attacker with network access over HTTPS to compromise the application. An attacker can take full control of Oracle Report Manager, gaining confidentiality, integrity, and availability for the affected system. The weakness is improper authentication and privilege escalation, classified as CWE-284, and is quantified by a CVSS 3.1 base score of 8.8.

Affected Systems

Oracle Report Manager, part of Oracle E‑Business Suite, affects the 12.2.x series from version 12.2.3 through 12.2.15. All installations of these versions that expose the HTTPS interface are susceptible to the vulnerability.

Risk and Exploitability

The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates that the attack can be performed by a network adversary with low privileges and no user interaction. The EPSS score of <1% suggests a low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the high severity score and potential for full application takeover warrant prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 10:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch for Oracle Report Manager as soon as it becomes available.
  • Restrict HTTPS access to the Report Manager service by configuring firewall or network segmentation to trusted internal networks.
  • Review and restrict low‑privileged accounts that can log into Report Manager, removing unused or unnecessary users.
  • If a vendor fix is not yet released, temporarily isolate the Report Manager service using network isolation or a honeypot to reduce exposure.

Generated by OpenCVE AI on September 20, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle Report Manager over HTTPS by Low-Privileged Attack

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle Report Manager via HTTPS
Weaknesses CWE-269
CWE-307

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle Report Manager via HTTPS
Weaknesses CWE-269
CWE-307

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Report Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle report Manager
CPEs cpe:2.3:a:oracle:report_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle report Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Report Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:19:05.967Z

Reserved: 2026-08-31T15:40:57.341Z

Link: CVE-2026-83122

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:50.504Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:22.600

Modified: 2026-09-17T16:18:03.770

Link: CVE-2026-83122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:30:17Z

Weaknesses