Description
Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Report Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Report Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access and Partial Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper access control flaw (CWE-284) in Oracle Report Manager. It allows a low-privileged attacker with network connectivity over HTTPS to gain unauthorized access to critical data and to all data that is normally protected by Report Manager. Successful exploitation can also induce a partial denial of service, reducing the availability of the application. The flaw does not appear to affect data integrity.

Affected Systems

Oracle Report Manager, part of Oracle E-Business Suite, is affected in supported releases 12.2.3 through 12.2.15. The vulnerability is present in the Internal Operations component and is relevant for deployments that expose the HTTPS interface to external or internal users with limited privileges.

Risk and Exploitability

The CVSS score of 7.1 places the issue in the high-severity range, while the EPSS score of less than 1% indicates a very low probability that the flaw will be exploited in the wild. The flaw is not currently listed in CISA’s KEV catalog. Exploitation requires network access to the HTTPS service and a non-privileged user account, making it relatively easy for an attacker who can reach the Report Manager endpoint to leverage the flaw. Because the damage includes both confidentiality loss and partial disruption, the overall risk remains significant despite the low EPSS score.

Generated by OpenCVE AI on September 18, 2026 at 20:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Report Manager patch for versions 12.2.3-12.2.15 that addresses the access control flaw.
  • Limit network access to the Report Manager service to trusted IP ranges or internal networks.
  • Review and tighten user role definitions to ensure only necessary privileges are granted for Report Manager operations.

Generated by OpenCVE AI on September 18, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service via Low Privileged HTTPS in Oracle Report Manager

Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service via Low Privileged HTTPS in Oracle Report Manager

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Report Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Report Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle report Manager
CPEs cpe:2.3:a:oracle:report_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle report Manager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Report Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:57:42.575Z

Reserved: 2026-08-31T15:40:57.341Z

Link: CVE-2026-83123

cve-icon Vulnrichment

Updated: 2026-09-16T17:56:11.104Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:22.720

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T03:45:17Z

Weaknesses