Description
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. While the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to critical data and partial denial of service
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the Documents component of Oracle One-to-One Fulfillment within Oracle E‑Business Suite. A low‑privileged attacker who can reach the application over HTTP can exploit this issue to gain unauthorized access to critical data and cause a partial denial of service. The flaw allows the attacker to read sensitive information and disrupt availability when accessed through a standard web interface, without requiring elevated user rights or interaction from the victim.

Affected Systems

Oracle Corporation’s Oracle One-to-One Fulfillment product is affected in versions 12.2.3 through 12.2.15. The advisory notes that the vulnerability may have a scope change, potentially impacting additional Oracle products that interact with the affected module.

Risk and Exploitability

The CVSS score of 7.1 reflects a high severity with substantial confidentiality impact and moderate availability impact. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based via HTTP to the Oracle One-to-One Fulfillment service; the attacker requires only low privileges on the network. Given the high confidentiality impact and the potential for service disruption, organizations should treat this as a priority for remediation.

Generated by OpenCVE AI on September 17, 2026 at 01:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Oracle One-to-One Fulfillment security patch for versions 12.2.3‑12.2.15 as released by Oracle.
  • Restrict HTTP access to the One-to-One Fulfillment application to trusted internal networks or subscribed partners to limit exposure to low‑privileged attackers.
  • Enforce strict role‑based access controls and only grant the minimum required privileges to users interacting with the Documents module.
  • Implement continuous monitoring of application logs for anomalous read or denial‑of‑service activity and trigger alerts for suspicious patterns.

Generated by OpenCVE AI on September 17, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service via Low-Privilege HTTP Attack in Oracle One-to-One Fulfillment
Weaknesses CWE-284
CWE-363

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. While the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L).
First Time appeared Oracle
Oracle one-to-one Fulfillment
CPEs cpe:2.3:a:oracle:one-to-one_fulfillment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle one-to-one Fulfillment
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Oracle One-to-one Fulfillment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:04:09.905Z

Reserved: 2026-08-31T15:40:57.344Z

Link: CVE-2026-83171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:28.103

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T01:30:08Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-363

    Race Condition Enabling Link Following