Description
Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and unauthorized access to critical data
Action: Apply Patch
AI Analysis

Impact

A vulnerability exists in the CRM User Management Framework of Oracle Common Applications that allows a low‑privileged attacker with network access via HTTP to compromise the application. The flaw requires the attacker to obtain user interaction from a person other than the attacker, but once triggered it can lead to unauthorized creation, deletion, or modification of data and unauthorized access to all data that the application can reach. The weakness is an improper authorization flaw that permits elevated permissions without proper validation, resulting in confidentiality and integrity breaches.

Affected Systems

Oracle Common Applications, part of Oracle E‑Business Suite, is affected by the flaw in versions 12.2.3 through 12.2.15. The vulnerability is present in the CRM User Management Framework component of this product, delivered by Oracle Corporation.

Risk and Exploitability

The CVSS v3.1 score of 7.3 indicates a high‑severeness impact. The EPSS score is below 1%, suggesting a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires HTTP access and a low‑privileged attacker who can obtain user interaction, which limits the attack surface yet still poses a significant threat to confidentiality and integrity for systems that expose the application over the network.

Generated by OpenCVE AI on September 20, 2026 at 09:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a fixed version as specified in the Oracle security advisory
  • Restrict HTTP access to Oracle Common Applications by implementing network segmentation or firewall rules
  • Enforce least‑privilege access controls on the CRM User Management Framework and disable unused features

Generated by OpenCVE AI on September 20, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification Via Low‑Privilege HTTP Attack in Oracle Common Applications

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Oracle Common Applications CRM User Management Framework Enables Low‑Privileged Data Manipulation
Weaknesses CWE-285

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Oracle Common Applications CRM User Management Framework Enables Low‑Privileged Data Manipulation
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications accessible data as well as unauthorized access to critical data or complete access to all Oracle Common Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle common Applications
CPEs cpe:2.3:a:oracle:common_applications:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle common Applications
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Common Applications
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:15:28.315Z

Reserved: 2026-08-31T15:40:57.345Z

Link: CVE-2026-83185

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:25.850Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:29.690

Modified: 2026-09-17T16:18:08.153

Link: CVE-2026-83185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:15:17Z

Weaknesses