Description
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: System Compromise
Action: Immediate Patch
AI Analysis

Impact

Easily exploitable vulnerability in Oracle Spares Management within Oracle E‑Business Suite allows a low‑privileged attacker with network access via HTTP to compromise the application. Because the flaw grants significant confidentiality, integrity, and availability impact, an attacker can effectively take over the Oracle Spares Management component, achieving full control of the service and potentially impacting other parts of the E‑Business Suite. The vulnerability stems from an access control weakness, classified as CWE‑284.

Affected Systems

Oracle Spares Management in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. The Internal Operations component is the only part impacted by this vulnerability.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 indicates a high severity risk, with significant impacts to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is HTTP traffic to the Spares Management service from a low‑privileged user who can exploit insufficient access controls to achieve takeover. No additional access or privilege escalation requirements are mentioned beyond these conditions.

Generated by OpenCVE AI on September 20, 2026 at 10:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a version where the issue is fixed.
  • Restrict network access to the Oracle Spares Management service to trusted hosts or networks only.
  • Enforce strict access control policies, ensuring the application user account operates with the least privilege necessary.
  • Monitor HTTP traffic and application logs for suspicious activity targeting the Spares Management endpoints.

Generated by OpenCVE AI on September 20, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploit Enables Takeover of Oracle Spares Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Spares Management Remote Code Execution via HTTP by Low Privileged Attacker
Weaknesses CWE-272

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Oracle Spares Management Remote Code Execution via HTTP by Low Privileged Attacker
Weaknesses CWE-272
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle spares Management
CPEs cpe:2.3:a:oracle:spares_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle spares Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Spares Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:18:18.230Z

Reserved: 2026-08-31T15:40:57.342Z

Link: CVE-2026-83137

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:43.745Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:24.413

Modified: 2026-09-17T16:18:04.710

Link: CVE-2026-83137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:30:17Z

Weaknesses