Description
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks of this vulnerability can result in takeover of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution and full system takeover
Action: Immediate Patch
AI Analysis

Impact

The vulnerability originates from a Java Server issue in Oracle One-to-One Fulfillment, allowing an unauthenticated attacker to compromise the application through an HTTP request. Successful exploitation grants the attacker full control over the system, enabling alteration of data, execution of arbitrary code, and potential disruption of all business processes. The weakness leads to complete loss of confidentiality, integrity, and availability for the compromised instance.

Affected Systems

The-One Fulfillment, part of Oracle E‑Business Suite, for all supported versions from 12.2.3 through 12.2.15. The vulnerability is tied to the Java Server component, which processes incoming HTTP requests. No other vendors or products are listed.

Risk and Exploitability

The CVSS base score of 8.1 indicates a high severity. The exploit requires only network access over HTTP with no user credentials, and the attack complexity is high, meaning it is not trivial, but the lack of required privileges and user interaction lower the barrier. The EPSS score of less than 1% suggests that, currently, the likelihood of exploitation is very low, and the vulnerability is not in the CISA KEV catalog. Nevertheless, the availability of the issue and its remote impact warrant proactive remediation, as attackers could mount remote code execution by crafting specific HTTP requests.

Generated by OpenCVE AI on September 17, 2026 at 01:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that fixes the Java Server issue in Oracle One-to-One Fulfillment for versions 12.2.3 to 12.2.15.
  • Restrict inbound HTTP access to the Oracle One-to-One networks by using firewall or network segmentation.
  • Enforce HTTPS and configure strict TLS settings to mitigate the risk of interception or tampering during HTTP communication.
  • Enable or enforce multi‑factor authentication for any administrative interfaces to limit the impact of compromised credentials.

Generated by OpenCVE AI on September 17, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle One-to-One Fulfillment via HTTP
Weaknesses CWE-502

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks of this vulnerability can result in takeover of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle one-to-one Fulfillment
CPEs cpe:2.3:a:oracle:one-to-one_fulfillment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle one-to-one Fulfillment
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle One-to-one Fulfillment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:44.546Z

Reserved: 2026-08-31T15:40:57.344Z

Link: CVE-2026-83169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:27.887

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T01:30:08Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data