Description
Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Immediate Patch
AI Analysis

Impact

The Oracle XML Gateway vulnerability is a remotely exploitable flaw that permits a low‑privileged attacker with network access through HTTP to gain unauthorized access to critical data or to take full control of the gateway’s accessible data. Successful exploitation can also trigger a partial denial of service, reducing the gateway’s availability. The weakness is reflected in a CVSS 3.1 Base score of 7.1, indicating high confidentiality impact and moderate availability impact.

Affected Systems

Affected are Oracle XML Gateway components of Oracle E‑Business Suite in versions 12.2.3 through 12.2.15, as specified by the vendor.

Risk and Exploitability

This is a network‑based threat; the attacker only needs HTTP connectivity to the gateway and no elevated privileges. The EPSS score is less than 1 %, suggesting that exploitation attempts are currently uncommon, and it is not listed in CISA’s KEV catalog. Nonetheless, the confirmed ability to exfiltrate sensitive data or disrupt service warrants immediate attention. The CVSS score of 7.1 quantifies the risk of insecure access and potential service degradation if the vulnerability is left unpatched.

Generated by OpenCVE AI on September 22, 2026 at 19:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Oracle XML Gateway to a version later than 12.2.15 where the vulnerability is fixed.
  • Restrict HTTP access to the XML Gateway to trusted networks or enforce VPN and firewall rules to limit exposure.
  • Ensure that authentication and authorization controls are correctly enforced on all interfaces and monitor logs for anomalous access attempts.

Generated by OpenCVE AI on September 22, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via Oracle XML Gateway HTTP Access

Tue, 22 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Exploit Allows Unauthorized Data Access and Partial DoS in Oracle XML Gateway
Weaknesses CWE-284
CWE-285
CWE-770

Tue, 22 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Sun, 20 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Exploit Allows Unauthorized Data Access and Partial DoS in Oracle XML Gateway
Weaknesses CWE-284
CWE-285
CWE-770

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle XML Gateway Unauthorized Access via HTTP
Weaknesses CWE-284
CWE-290

Wed, 16 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Oracle XML Gateway Unauthorized Access via HTTP
Weaknesses CWE-284
CWE-290

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle xml Gateway
CPEs cpe:2.3:a:oracle:xml_gateway:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle xml Gateway
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Xml Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T14:50:34.234Z

Reserved: 2026-08-31T15:40:57.351Z

Link: CVE-2026-83300

cve-icon Vulnrichment

Updated: 2026-09-22T14:50:14.290Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:42.873

Modified: 2026-09-22T15:17:17.040

Link: CVE-2026-83300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor