Description
Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Proposals. While the vulnerability is in Oracle Proposals, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Proposals accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access
Action: Apply Fix
AI Analysis

Impact

A flaw in the Oracle Proposals component of Oracle E‑Business Suite permits a low‑privileged user with network connectivity to the HTTP service to gain unauthorized access to confidential proposal data. The vulnerability, which is easy to exploit, can lead to reading or obtaining all data available through Oracle Proposals, and the vendor indicates a potential scope change that could affect other products in the same environment. The weakness is classified under CWE‑284, reflecting the absence or misimplementation of proper authorization controls.

Affected Systems

Oracle Proposals versions 12.2.3 through 12.2.15 are affected. All installations of these releases that expose the HTTP interface to the network are vulnerable, and the scope change suggests that other Oracle E‑Business Suite components might also be impacted if they share the same authentication mechanisms.

Risk and Exploitability

The base CVSS score of 7.7 indicates a significant impact on confidentiality, while the EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, implying a low current exploitation probability. Attacking the flaw requires only network access over HTTP and a low‑privilege account; no user interaction is needed. If successfully leveraged, the attacker could obtain full access to the data exposed by Oracle Proposals, compromising data privacy and potentially exposing sensitive business information.

Generated by OpenCVE AI on September 18, 2026 at 21:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any Oracle security patch or update released for Oracle Proposals 12.2.3‑12.2.15 by visiting Oracle’s security alert page or consulting Oracle Support.
  • Reduce exposure by restricting HTTP access to the Oracle Proposals service to a limited set of trusted hosts or through VPN/internal networks; block public‑facing connections if not required.
  • Disable or remove the Oracle Proposals feature or associated modules when the functionality is not needed, or enforce strict role‑based access controls to limit privileges required to interact with the service.
  • Monitor audit logs for abnormal activity on the Oracle Proposals endpoints and verify that used accounts have the minimal privileges necessary.

Generated by OpenCVE AI on September 18, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP in Oracle Proposals

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP in Oracle Proposals
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Proposals. While the vulnerability is in Oracle Proposals, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Proposals accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle proposals
CPEs cpe:2.3:a:oracle:proposals:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle proposals
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Proposals
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:17:51.525Z

Reserved: 2026-08-31T15:40:57.342Z

Link: CVE-2026-83142

cve-icon Vulnrichment

Updated: 2026-09-17T14:22:53.939Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:24.850

Modified: 2026-09-17T16:18:05.290

Link: CVE-2026-83142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:15:14Z

Weaknesses