Description
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager. While the vulnerability is in Oracle Applications Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A vulnerability has been identified in the Oracle Applications Manager component known as Command Line – RapidClone. An attacker who already possesses high‑level privileges and can reach the system through the HTTP interface could trigger this flaw, allowing them to fully compromise the Applications Manager instance. The flaw would enable an operator to alter confidentiality, integrity and availability settings, effectively taking over the application. The CVSS 3.1 vector (AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H) reflects this remote impact.

Affected Systems

The affected product is Oracle Corporation’s Oracle Applications Manager, part of Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 inclusive are impacted. The vulnerability is present within the Command Line – RapidClone feature of these releases.

Risk and Exploitability

The base CVSS score of 8.0 indicates high severity. The EPSS score is below 1%, suggesting that active exploitation is unlikely but not impossible. Because the flaw can be leveraged by a privileged insider or malicious actor with network access, the risk is significant for any organization that runs these versions on exposed networks. It is not currently listed in the CISA KEV catalog, but the potential for full system takeover warrants immediate attention.

Generated by OpenCVE AI on September 17, 2026 at 01:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses CVE‑2026‑83157 to all affected Systems
  • Restrict HTTP access to the Applications Manager server to only trusted hosts or internal networks
  • Disable or remove the RapidClone command line feature if it is not required for business operations

Generated by OpenCVE AI on September 17, 2026 at 01:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via RapidClone Command Line in Oracle Applications Manager
Weaknesses CWE-77

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager. While the vulnerability is in Oracle Applications Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Manager
CPEs cpe:2.3:a:oracle:applications_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Manager
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:17:21.822Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83157

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:39.589Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:26.553

Modified: 2026-09-17T16:18:05.857

Link: CVE-2026-83157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T01:45:06Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')