Description
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Technical Foundation accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Patch Immediately
AI Analysis

Impact

A vulnerability in Oracle CRM Technical Foundation allows an attacker who can reach or modify data without proper authorization, compromising the confidentiality and integrity of critical information. The weakness arises from inadequate access control that permits low‑privileged users to perform privileged operations.

Affected Systems

Oracle Corporation’s Oracle CRM Technical Foundation, part of Oracle E‑Business Suite, is affected for versions 12.2.3 through 12.2.15. This includes the Application Framework component that handles data manipulation via HTTP endpoints.

Risk and Exploitability

The CVSS v3.1 Base Score of 8.1 indicates a high severity issue that can be exploited easily, with an attack vector of network and required privileges of low. The EPSS score of < 1% shows a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker with network access to the CRM’s HTTP interface can leverage the flaw to elevate their capabilities and permanently alter or delete data, impacting business operations.

Generated by OpenCVE AI on September 17, 2026 at 01:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for Oracle CRM Technical Foundation 12.2.3 through 12.2.15 to remediate the access control flaw.
  • Restrict HTTP or network ACLs to allow only trusted hosts to reach the vulnerable endpoints.
  • Review and enforce stricter access control policies within the CRM to ensure that only authorized users can create, delete, or modify critical data.

Generated by OpenCVE AI on September 17, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Vulnerability Enabling Unauthorized Data Manipulation in Oracle CRM Technical Foundation
Weaknesses CWE-284
CWE-732

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle CRM Technical Foundation accessible data as well as unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle crm Technical Foundation
CPEs cpe:2.3:a:oracle:crm_technical_foundation:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle crm Technical Foundation
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Crm Technical Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:04:10.864Z

Reserved: 2026-08-31T15:40:57.344Z

Link: CVE-2026-83174

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:28.440

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T01:30:08Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-732

    Incorrect Permission Assignment for Critical Resource