Description
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Full Application Compromise
Action: Immediate Patch
AI Analysis

Impact

The Oracle Spares Management module of Oracle E‑Business Suite contains a vulnerability that allows an attacker with low privileges and network access over HTTP to compromise the application. The flaw enables the attacker to gain full control of the application, potentially exfiltrating data or disrupting services. The weakness manifests as improper access control (CWE-284).

Affected Systems

The affected product is Oracle Spares Management from Oracle Corporation, specifically the Internal Operations component of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are affected, as identified by the vendor and the cpe:2.3:a:oracle:spares_management:*:*:*:*:*:*:* entry.

Risk and Exploitability

The vulnerability scored a CVSS base score of 8.8, signifying high severity. The EPSS score of less than 1% indicates that, at present, the likelihood of exploit in the wild is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only HTTP access and a low‑privileged attacker; thus an adversary on the network can potentially gain full control over the application, leading to data exfiltration or service disruption.

Generated by OpenCVE AI on September 20, 2026 at 09:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch for Oracle Spares Management as soon as it becomes available
  • Block or restrict HTTP traffic to the Oracle Spares Management service from untrusted networks
  • Verify that the target system is not exposed to the public internet and enforce strict firewall rules

Generated by OpenCVE AI on September 20, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Spares Management Enables Full Compromise

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Spares Management Remote Code Execution via HTTP
Weaknesses CWE-78

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Oracle Spares Management Remote Code Execution via HTTP
Weaknesses CWE-78

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle spares Management
CPEs cpe:2.3:a:oracle:spares_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle spares Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Spares Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:18:23.610Z

Reserved: 2026-08-31T15:40:57.342Z

Link: CVE-2026-83136

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:45.390Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:24.303

Modified: 2026-09-17T16:18:04.563

Link: CVE-2026-83136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:30:18Z

Weaknesses