Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Patch if Available
AI Analysis

Impact

The vulnerability in Oracle Application Object Library (CWE‑284) permits an unauthenticated attacker with network access over HTTP to gain authority to create, delete, or modify critical data or to gain full access to all data exposed by the library. This leads to high impacts to confidentiality and integrity, as documented by a CVSS score of 7.4.

Affected Systems

Affected versions are Oracle E‑Business Suite Oracle Application Object Library 12.2.3 through 12.2.15, released by Oracle Corporation.

Risk and Exploitability

The weakness is exploitable from any networked host that can reach the HTTP endpoint, requiring high effort but no authentication. The EPSS score is less than 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Despite the low EPSS, the high CVSS score and the potential for unauthorized data modification warrant careful monitoring and mitigation.

Generated by OpenCVE AI on September 18, 2026 at 19:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any Oracle patch or upgrade that addresses this issue.
  • Limit HTTP access to the affected application to trusted internal networks or VPNs, enforcing strict network segmentation.
  • Enable logging and regularly audit access and permission changes to detect unauthorized activity.

Generated by OpenCVE AI on September 18, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Application Object Library

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Application Object Library
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:15:35.010Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83184

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:26.797Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:29.580

Modified: 2026-09-17T16:18:08.017

Link: CVE-2026-83184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:15:14Z

Weaknesses