Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and access
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises in the Oracle Application Object Library component of Oracle E-Business Suite. An unauthenticated attacker with network access to HTTPS can compromise the library, enabling unauthorized creation, deletion, modification, or complete access to critical data. The flaw represents an improper authorization weakness that results in confidentiality and integrity impacts as reflected in the CVSS vector.

Affected Systems

Oracle Corporation’s Oracle Application Object Library, part of Oracle E-Business Suite Core, is affected in versions 12.2.3 through 12.2.15. Users of these releases are at risk if the vulnerable component remains unpatched.

Risk and Exploitability

The CVSS Base Score of 7.4 indicates high severity for confidentiality and integrity. The EPSS score of less than 1% and the vulnerability is not listed in CISA’s KEV catalog. Attackers must be able to reach the HTTPS interface of the library; no credentials are required. Because the vulnerability is described as difficult to exploit, successful attacks will grant the attacker significant data access but are unlikely to impact availability. The overall risk low in exploitation likelihood.

Generated by OpenCVE AI on September 17, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or patch Oracle Application Object Library to a version that resolves CVE-2026-83162.
  • Restrict HTTPS access to the Application Object Library by employing network segmentation or firewall rules to allow only trusted hosts.
  • Monitor audit logs and alerts for unauthorized CRUD operations against Oracle Application Object Library to detect potential exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Based Data Modification in Oracle Application Object Library
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:16:52.674Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83162

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:35.397Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:27.120

Modified: 2026-09-17T16:18:06.570

Link: CVE-2026-83162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T01:30:08Z

Weaknesses