Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Compromise
Action: Immediate Patch
AI Analysis

Impact

A publicly accessible HTTP endpoint in Oracle Application Object Library makes the system vulnerable to unauthenticated attacks that can leak sensitive data. An attacker can read critical information stored within the library without needing credentials, potentially exposing personal, financial, or strategic data. The vulnerability does not allow code execution or denial of service, but the loss of confidentiality can severely impact the organization’s compliance and trust.

Affected Systems

Oracle Corporation’s Oracle Application Object Library component of E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 are listed as vulnerable. No other vendors or product variants are indicated, and the vulnerability is specific to the Core product within the suite.

Risk and Exploitability

The CVSS 3.1 base score is 7.5, reflecting a high severity of confidentiality impact. The EPSS score is less than 1%, indicating a low exploitation probability in the current landscape, and the issue is not listed in the CISA KEV catalog. The vulnerability is exploitable over the network via HTTP in an unauthenticated session; the likely attack path involves a remote client issuing specially crafted requests to the exposed endpoint. As no authentication is required, an attacker with network access can exploit this flaw whenever the affected library is reachable.

Generated by OpenCVE AI on September 17, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or update referenced in Oracle’s security alert for CVE-2026-83167
  • Restrict external network access to the Oracle Application Object Library by configuring firewall rules or network segmentation
  • Disable anonymous or unauthenticated HTTP access to the library and enforce proper user authentication for all requests

Generated by OpenCVE AI on September 17, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Exposure in Oracle Application Object Library
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:43.888Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83167

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:27.670

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T01:30:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control