Description
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote takeover of Oracle Applications Manager via low‑privileged HTTPS access
Action: Patch urgently
AI Analysis

Impact

A vulnerability in Oracle Applications Manager allows an attacker with low privileges but network connectivity through HTTPS to compromise the system. The flaw results in full control of Oracle Applications Manager, enabling the attacker to execute arbitrary commands, modify configuration, and exfiltrate sensitive data. The impact covers confidentiality, integrity, and availability, signifying a complete takeover of the affected application.

Affected Systems

Oracle Corporation’s Oracle Applications Manager within Oracle E‑Business Suite, specifically the Oracle Diagnostics Interfaces component. The affected releases are 12.2.3 through 12.2.15. Systems running any of these versions with external or internalHTTPS access remain vulnerable.

Risk and Exploitability

The CVSS 3.1 Base Score of 8.8 indicates a high severity, with the vector pointing to network‑reachable, authenticated low‑priv, integrity, and availability compromise. The EPSS score of less than 1 % suggests that the explosive probability is currently low, but the lack of a CISA KEV listing does not diminish the need for immediate mitigation. The attack vector is inferred to be HTTPS‐based network traffic, requiring network access but not privileged credentials.

Generated by OpenCVE AI on September 17, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Oracle patch that addresses vulnerability CVE‑2026‑83168 for all affected versions (12.2.3‑12.2.15).
  • Restrict HTTPS access to Oracle Applications Manager to trusted IP ranges or VPN only, reducing exposure to potential attackers.
  • Implement continuous monitoring of access logs for unusual authentication patterns and enforce strong authentication controls to prevent low‑privilege attackers from exploiting the vulnerability.

Generated by OpenCVE AI on September 17, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle Applications Manager via Low‑Privileged HTTPS
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle applications Manager
CPEs cpe:2.3:a:oracle:applications_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle applications Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Applications Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:43.333Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83168

cve-icon Vulnrichment

Updated: 2026-09-17T13:02:07.793Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:27.773

Modified: 2026-09-17T14:17:34.783

Link: CVE-2026-83168

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T01:30:08Z

Weaknesses