Description
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Spares Management. While the vulnerability is in Oracle Spares Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: High-Privilege Remote Compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Oracle Spares Management allows an attacker who already possesses high privileges and has network access via HTTP to compromise the system. Successful exploitation can lead to a full takeover of Oracle Spares Management, resulting in confidentiality, integrity, and availability loss across the affected product. The impact may extend to other Oracle products that interact with it due to a scope change, underscoring the need for strict access controls and proper authentication verification.

Affected Systems

Affected versions are 12.2.3 through 12.2.15 of Oracle Spares Management, part of Oracle E‑Business Suite. The impact may extend beyond this component to other Oracle products that interact with it due to a scope change.

Risk and Exploitability

The CVSS 3.1 Base Score of 8.0 indicates high severity. The EPSS score is less than 1 %, suggesting a low probability of exploit at this time, and it is not listed in the CISA KEV catalog. Nevertheless, the remote attack vector via HTTP and the potential to affect other products means that the risk remains significant, especially for systems still running the affected versions.

Generated by OpenCVE AI on September 18, 2026 at 21:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch that addresses the vulnerability for versions 12.2.3 through 12.2.15.
  • Restrict network access to Oracle Spares Management to trusted hosts or networks and use firewall rules.
  • Monitor system and application logs for signs of unauthorized access attempts.
  • Review and update the configuration of other Oracle E‑Business Suite components that interact with Spares Management to mitigate any downstream impact.

Generated by OpenCVE AI on September 18, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Remote Compromise of Oracle Spares Management via HTTP

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title High-Privilege Remote Compromise of Oracle Spares Management via HTTP
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Spares Management. While the vulnerability is in Oracle Spares Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle spares Management
CPEs cpe:2.3:a:oracle:spares_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle spares Management
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Spares Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:18:12.129Z

Reserved: 2026-08-31T15:40:57.342Z

Link: CVE-2026-83138

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:42.587Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:24.527

Modified: 2026-09-17T16:18:04.850

Link: CVE-2026-83138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:15:14Z

Weaknesses